Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5m2v-hc64-56h6

Опубликовано: 30 сент. 2019
Источник: github
Github: Прошло ревью
CVSS3: 5.5

Описание

Rubyzip denial of service

In Rubyzip before 1.3.0, a crafted ZIP file can bypass application checks on ZIP entry sizes because data about the uncompressed size can be spoofed. This allows attackers to cause a denial of service (disk consumption).

Пакеты

Наименование

rubyzip

rubygems
Затронутые версииВерсия исправления

< 1.3.0

1.3.0

EPSS

Процентиль: 40%
0.0018
Низкий

5.5 Medium

CVSS3

Дефекты

CWE-400

Связанные уязвимости

CVSS3: 5.5
ubuntu
больше 6 лет назад

In Rubyzip before 1.3.0, a crafted ZIP file can bypass application checks on ZIP entry sizes because data about the uncompressed size can be spoofed. This allows attackers to cause a denial of service (disk consumption).

CVSS3: 5.5
redhat
больше 6 лет назад

In Rubyzip before 1.3.0, a crafted ZIP file can bypass application checks on ZIP entry sizes because data about the uncompressed size can be spoofed. This allows attackers to cause a denial of service (disk consumption).

CVSS3: 5.5
nvd
больше 6 лет назад

In Rubyzip before 1.3.0, a crafted ZIP file can bypass application checks on ZIP entry sizes because data about the uncompressed size can be spoofed. This allows attackers to cause a denial of service (disk consumption).

CVSS3: 5.5
debian
больше 6 лет назад

In Rubyzip before 1.3.0, a crafted ZIP file can bypass application che ...

EPSS

Процентиль: 40%
0.0018
Низкий

5.5 Medium

CVSS3

Дефекты

CWE-400