1.7.0
19 years ago
17 years ago
Known vulnerabilities in the ant:ant package. This does not include vulnerabilities belonging to this package’s dependencies.
Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for freeVulnerability | Vulnerable Version |
---|---|
ant:ant is a deprecated package, users looking to upgrade to fixed versions of the maintained package should move to Affected versions of this package are vulnerable to Denial of Service (DoS). When reading a specially crafted ZIP archive, or a derived format, an Apache Ant build can be made to allocate large amounts of memory that leads to an out of memory error, even for small inputs. This can be used to disrupt builds using Apache Ant. Commonly used derived formats of ZIP archives include JAR files. How to fix Denial of Service (DoS)? There is no fixed version for | [0,) |
ant:ant is a deprecated package, users looking to upgrade to fixed versions of the maintained package should move to Affected versions of this package are vulnerable to Denial of Service (DoS). When reading a specially crafted TAR archive an Apache Ant build can be made to allocate large amounts of memory that finally leads to an out of memory error, even for small inputs. How to fix Denial of Service (DoS)? There is no fixed version for | [0,) |
ant:ant is a deprecated package, users looking to upgrade to fixed versions of the maintained package should move to Affected versions of this package are vulnerable to Insecure Default. It uses the default temporary directory identified by the Java system property How to fix Insecure Default? There is no fixed version for | [0,) |