CVE-2024-25710

Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in Apache Commons Compress.This issue affects Apache Commons Compress: from 1.3 through 1.25.0. Users are recommended to upgrade to version 1.26.0 which fixes the issue.
Configurations

Configuration 1 (hide)

cpe:2.3:a:apache:commons_compress:*:*:*:*:*:*:*:*

History

13 Feb 2025, 18:17

Type Values Removed Values Added
Summary (en) Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in Apache Commons Compress.This issue affects Apache Commons Compress: from 1.3 through 1.25.0. Users are recommended to upgrade to version 1.26.0 which fixes the issue. (en) Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in Apache Commons Compress.This issue affects Apache Commons Compress: from 1.3 through 1.25.0. Users are recommended to upgrade to version 1.26.0 which fixes the issue.

21 Nov 2024, 09:01

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 5.5
v2 : unknown
v3 : 8.1
References () http://www.openwall.com/lists/oss-security/2024/02/19/1 - Mailing List, Third Party Advisory () http://www.openwall.com/lists/oss-security/2024/02/19/1 - Mailing List, Third Party Advisory
References () https://lists.apache.org/thread/cz8qkcwphy4cx8gltn932ln51cbtq6kf - Vendor Advisory () https://lists.apache.org/thread/cz8qkcwphy4cx8gltn932ln51cbtq6kf - Vendor Advisory
References () https://security.netapp.com/advisory/ntap-20240307-0010/ - () https://security.netapp.com/advisory/ntap-20240307-0010/ -

07 Mar 2024, 17:15

Type Values Removed Values Added
References
  • () https://security.netapp.com/advisory/ntap-20240307-0010/ -

22 Feb 2024, 15:24

Type Values Removed Values Added
References () https://lists.apache.org/thread/cz8qkcwphy4cx8gltn932ln51cbtq6kf - () https://lists.apache.org/thread/cz8qkcwphy4cx8gltn932ln51cbtq6kf - Vendor Advisory
References () http://www.openwall.com/lists/oss-security/2024/02/19/1 - () http://www.openwall.com/lists/oss-security/2024/02/19/1 - Mailing List, Third Party Advisory
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.5
CPE cpe:2.3:a:apache:commons_compress:*:*:*:*:*:*:*:*
First Time Apache
Apache commons Compress

19 Feb 2024, 11:15

Type Values Removed Values Added
References
  • () http://www.openwall.com/lists/oss-security/2024/02/19/1 -

19 Feb 2024, 09:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-02-19 09:15

Updated : 2025-02-13 18:17


NVD link : CVE-2024-25710

Mitre link : CVE-2024-25710

CVE.ORG link : CVE-2024-25710


JSON object : View

Products Affected

apache

  • commons_compress
CWE
CWE-835

Loop with Unreachable Exit Condition ('Infinite Loop')