Rewterz

Rewterz Threat Advisory – Multiple Mozilla Firefox Vulnerabilities

July 14, 2021
Rewterz

Rewterz Threat Alert – Lokibot Malware – Active IOCs

July 14, 2021

Rewterz Threat Advisory – Multiple Apache Vulnerabilities

Severity

High

Analysis Summary

CVE-2021-35515

Apache Commons Compress is vulnerable to a denial of service, caused by an infinite loop flaw in the construction of the list of codecs that decompress an entry. By persuading a victim to open a specially-crafted 7Z archive, a remote attacker could exploit this vulnerability to cause a denial of service condition against services that use Compress’ sevenz package.

CVE-2021-35516

Apache Commons Compress is vulnerable to a denial of service, caused by an out-of-memory error when allocate large amounts of memory. By persuading a victim to open a specially-crafted 7Z archive, a remote attacker could exploit this vulnerability to cause a denial of service condition against services that use Compress’ sevenz package.

CVE-2021-35517

Apache Commons Compress is vulnerable to a denial of service, caused by an out-of-memory error when allocate large amounts of memory. By persuading a victim to open a specially-crafted TAR archive, a remote attacker could exploit this vulnerability to cause a denial of service condition against services that use Compress’ tar package.

CVE-2021-36090

Apache Commons Compress is vulnerable to a denial of service, caused by an out-of-memory error when allocate large amounts of memory. By persuading a victim to open a specially-crafted ZIP archive, a remote attacker could exploit this vulnerability to cause a denial of service condition against services that use Compress’ zip package.

CVE-2021-36373

Apache Ant is vulnerable to a denial of service, caused by an out-of-memory error when allocate large amounts of memory. By persuading a victim to open a specially-crafted TAR archive, a remote attacker could exploit this vulnerability to cause the application to crash.

CVE-2021-36374

Apache Ant is vulnerable to a denial of service, caused by an out-of-memory error when allocate large amounts of memory. By persuading a victim to open a specially-crafted ZIP archive, a remote attacker could exploit this vulnerability to cause the application to crash.

Impact

  • Denial of Service

Affected Vendors

Apache

Affected Product

Apache Commons Compress 1.6
Apache Commons Compress 1.20
Apache Ant 1.9
Apache Ant 1.10.0

Remediation

Upgrade to the latest version of Apache Commons Compress (1.21 or later), Apache Ant (1.9.16, 1.10.11 or later).

https://commons.apache.org/proper/commons-compress/

Reading this advisory was a good start.

Make it a habit.

Rewterz publishes threat advisories ahead of mainstream cybersecurity media, informed by an AI-Native Autonomous SOC that sees regional threat actor activity in real time. Subscribe to receive each new advisory as it publishes, plus a monthly Middle East threat landscape brief drawn from our own SOC telemetry. For teams evaluating their detection coverage, a 30-minute consultation with a senior analyst is also available, at your pace, when you're ready.


The Future of Autonomous Security Takes the Stage

11 August 2026 | 9:00 AM onwards
Pearl Continental Hotel, Karachi