CVE-2023-42503

CVSS 3.1 Score 5.5 of 10 (medium)

Details

Published Sep 14, 2023
Updated: Feb 21, 2024
CWE ID 400
CWE ID 20

Summary

CVE-2023-42503 represents an Improper Input Validation and Uncontrolled Resource Consumption vulnerability affecting Apache Commons Compress versions 1.22 and below. This issue arises from parsing PAX extended headers with file modification times that contain large or malformed numbers. The BigDecimal class, used for parsing these numbers, has a known algorithmic complexity issue, leading to hours-long processing times and a Denial of Service (DoS) attack via CPU exhaustion. The vulnerability is similar to CVE-2012-2098. To mitigate this risk, users are advised to upgrade to Apache Commons Compress version 1.24.0. Only applications utilizing CompressorStreamFactory, TarArchiveInputStream, and TarFile classes for parsing TAR files are susceptible to this issue, which was introduced in version 1.22.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Apache Commons Compress

Affected Vendors

  • Apache Software Foundation