CVE-2021-36373: Apache Ant TAR archive denial of service vulnerability
Apache Ant is vulnerable to a denial of service, caused by an out-of-memory error when large amounts of memory are allocated. By persuading a victim to open a specially-crafted TAR archive, a remote attacker could exploit this vulnerability to cause the application to crash.
Other sources
When reading a specially crafted TAR archive an Apache Ant build can be made to allocate large amounts of memory that finally leads to an out of memory error, even for small inputs. This can be used to disrupt builds using Apache Ant. Apache Ant prior to 1.9.16 and 1.10.11 were affected.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is vulnerability ID CVE-2021-36373?
Vulnerability ID CVE-2021-36373 is a denial of service vulnerability in Apache Ant.
How does vulnerability CVE-2021-36373 occur?
Vulnerability CVE-2021-36373 occurs when a specially crafted TAR archive is read by an Apache Ant build.
What is the impact of vulnerability CVE-2021-36373?
The impact of vulnerability CVE-2021-36373 is a denial of service caused by an out-of-memory error that can disrupt builds using Apache Ant.
Which versions of Apache Ant are affected by vulnerability CVE-2021-36373?
Vulnerability CVE-2021-36373 affects Apache Ant versions prior to 1.9.16 and 1.10.11.
How to mitigate vulnerability CVE-2021-36373?
To mitigate vulnerability CVE-2021-36373, it is recommended to update Apache Ant to version 1.9.16 or 1.10.11.