When reading a specially crafted TAR archive an Apache Ant build can be made to allocate large amounts of memory that finally leads to an out of memory error, even for small inputs. This can be used to disrupt builds using Apache Ant. Apache Ant prior to 1.9.16 and 1.10.11 were affected.
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade apache-ant | Aug 22, 2024 | Jul 14, 2021 |
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | Jul 14, 2021 |
| Debian | — | Upgrade ant | Jul 30, 2024 | Jul 14, 2021 |
| Huawei Euleros 2_0_sp3 | — | Upgrade ant | May 25, 2022 | Jul 14, 2021 |
| Huawei Euleros 2_0_sp5 | — | Upgrade ant | Nov 12, 2021 | Jul 14, 2021 |
| Huawei Euleros 2_0_sp8 | — | Upgrade ant-libUpgrade ant | Sep 24, 2021 | Jul 14, 2021 |
| Oracle Solaris | — | Upgrade developer/build/ant to version 1.10.11-11.4.39.0.1.107.0 on Solaris 11.4 | Nov 17, 2021 | Jul 14, 2021 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Jul 14, 2021 |
| Suse | — | Upgrade ant-scriptsUpgrade ant-junitUpgrade ant-jmfUpgrade ant-javamailUpgrade ant-commons-netUpgrade ant-junit5Upgrade ant-apache-oroUpgrade ant-jdependUpgrade ant-apache-log4jUpgrade ant-apache-xalan2Upgrade ant-swingUpgrade ant-xzUpgrade ant-imageioUpgrade ant-apache-bsfUpgrade antUpgrade ant-apache-resolverUpgrade ant-commons-loggingUpgrade ant-apache-bcelUpgrade ant-apache-regexpUpgrade ant-javadocUpgrade ant-jschUpgrade ant-antlrUpgrade ant-testutilUpgrade ant-manual | Oct 26, 2022 | Jul 14, 2021 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Jul 14, 2021 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub