Description
When reading a specially crafted ZIP archive, or a derived formats, an Apache Ant build can be made to allocate large amounts of memory that leads to an out of memory error, even for small inputs. This can be used to disrupt builds using Apache Ant. Commonly used derived formats from ZIP archives are for instance JAR files and many office files. Apache Ant prior to 1.9.16 and 1.10.11 were affected.
References (11)
Scores
CVSS v3
5.5
EPSS
0.0014
EPSS Percentile
33.7%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Details
CWE
CWE-130
Status
published
Products (50)
apache/ant
1.9.0 - 1.9.16
oracle/agile_engineering_data_management
6.2.1.0
oracle/agile_plm
9.3.6
oracle/banking_trade_finance
14.5
oracle/banking_treasury_management
14.5
oracle/communications_cloud_native_core_automated_test_suite
1.9.0
oracle/communications_cloud_native_core_binding_support_function
1.11.0
oracle/communications_diameter_intelligence_hub
8.0.0 - 8.1.0
oracle/communications_order_and_service_management
7.3
oracle/communications_order_and_service_management
7.4
... and 40 more
Published
Jul 14, 2021
Tracked Since
Feb 18, 2026