Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2020-22916

Опубликовано: 22 авг. 2023
Источник: debian

Описание

An issue discovered in XZ 5.2.5 allows attackers to cause a denial of service via decompression of a crafted file. NOTE: the vendor disputes the claims of "endless output" and "denial of service" because decompression of the 17,486 bytes always results in 114,881,179 bytes, which is often a reasonable size increase.

Примечания

  • Bogus CVE, original URL is gone and resource limits are a natural constraint for any unpacker

Связанные уязвимости

CVSS3: 5.5
ubuntu
больше 2 лет назад

An issue discovered in XZ 5.2.5 allows attackers to cause a denial of service via decompression of a crafted file. NOTE: the vendor disputes the claims of "endless output" and "denial of service" because decompression of the 17,486 bytes always results in 114,881,179 bytes, which is often a reasonable size increase.

CVSS3: 5.5
nvd
больше 2 лет назад

An issue discovered in XZ 5.2.5 allows attackers to cause a denial of service via decompression of a crafted file. NOTE: the vendor disputes the claims of "endless output" and "denial of service" because decompression of the 17,486 bytes always results in 114,881,179 bytes, which is often a reasonable size increase.

CVSS3: 5.5
github
больше 2 лет назад

An issue discovered in XZ 5.2.5 allows attackers to cause a denial of service via decompression of crafted file.