When reading a specially crafted TAR archive an Apache Ant build can be made to allocate large amounts of memory that finally leads to an out of memory error, even for small inputs. This can be used to disrupt builds using Apache Ant. Apache Ant prior to 1.9.16 and 1.10.11 were affected.
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade apache-ant | Aug 22, 2024 | Jul 14, 2021 |
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | Jul 14, 2021 |
| Debian | — | Upgrade ant | Jul 30, 2024 | Jul 14, 2021 |
| Huawei Euleros 2_0_sp3 | — | Upgrade ant | May 25, 2022 | Jul 14, 2021 |
| Huawei Euleros 2_0_sp5 | — | Upgrade ant | Nov 12, 2021 | Jul 14, 2021 |
| Huawei Euleros 2_0_sp8 | — | Upgrade antUpgrade ant-lib | Sep 24, 2021 | Jul 14, 2021 |
| Oracle Solaris | — | Upgrade developer/build/ant to version 1.10.11-11.4.39.0.1.107.0 on Solaris 11.4 | Nov 17, 2021 | Jul 14, 2021 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Jul 14, 2021 |
| Suse | — | Upgrade ant-testutilUpgrade ant-antlrUpgrade ant-jschUpgrade ant-apache-bcelUpgrade ant-commons-loggingUpgrade ant-manualUpgrade ant-apache-regexpUpgrade ant-javadocUpgrade ant-apache-resolverUpgrade ant-jmfUpgrade antUpgrade ant-xzUpgrade ant-junitUpgrade ant-imageioUpgrade ant-scriptsUpgrade ant-swingUpgrade ant-junit5Upgrade ant-jdependUpgrade ant-apache-xalan2Upgrade ant-apache-bsfUpgrade ant-apache-log4jUpgrade ant-commons-netUpgrade ant-apache-oroUpgrade ant-javamail | Oct 26, 2022 | Jul 14, 2021 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Jul 14, 2021 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub