CVE-2023-42503
CVSS 3.1 Score 5.5 of 10 (medium)
Details
Summary
CVE-2023-42503 represents an Improper Input Validation and Uncontrolled Resource Consumption vulnerability affecting Apache Commons Compress versions 1.22 and below. This issue arises from parsing PAX extended headers with file modification times that contain large or malformed numbers. The BigDecimal class, used for parsing these numbers, has a known algorithmic complexity issue, leading to hours-long processing times and a Denial of Service (DoS) attack via CPU exhaustion. The vulnerability is similar to CVE-2012-2098. To mitigate this risk, users are advised to upgrade to Apache Commons Compress version 1.24.0. Only applications utilizing CompressorStreamFactory, TarArchiveInputStream, and TarFile classes for parsing TAR files are susceptible to this issue, which was introduced in version 1.22.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Apache Commons Compress
Affected Vendors
- Apache Software Foundation