Description:

When reading a specially crafted ZIP archive, or a derived formats, an Apache 
Ant build can be made to allocate large amounts of memory that leads to an out 
of memory error, even for small inputs. This can be used to disrupt builds 
using Apache Ant.

Commonly used derived formats from ZIP archives are for instance JAR files and 
many office files.

Mitigation:

Apache Ant 1.9.x users should upgrade to 1.9.16 or later.
Apache Ant 1.10.x users should upgrade to 1.10.11 or later.

Credit:

This issue is similar to 
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-36090 present in Apache 
Commons Compress which has been detected by OSS Fuzz.

References:

https://ant.apache.org/security.html
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-36090

Reply via email to