Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-6cmv-pvcc-pf5h

Опубликовано: 09 апр. 2026
Источник: github
Github: Не прошло ревью

Описание

A memory exhaustion vulnerability exists in ZIP archive processing. Orthanc automatically extracts ZIP archives uploaded to certain endpoints and trusts metadata fields describing the uncompressed size of archived files. An attacker can craft a small ZIP archive containing a forged size value, causing the server to allocate extremely large buffers during extraction.

A memory exhaustion vulnerability exists in ZIP archive processing. Orthanc automatically extracts ZIP archives uploaded to certain endpoints and trusts metadata fields describing the uncompressed size of archived files. An attacker can craft a small ZIP archive containing a forged size value, causing the server to allocate extremely large buffers during extraction.

EPSS

Процентиль: 4%
0.00017
Низкий

Связанные уязвимости

ubuntu
5 дней назад

A memory exhaustion vulnerability exists in ZIP archive processing. Orthanc automatically extracts ZIP archives uploaded to certain endpoints and trusts metadata fields describing the uncompressed size of archived files. An attacker can craft a small ZIP archive containing a forged size value, causing the server to allocate extremely large buffers during extraction.

nvd
5 дней назад

A memory exhaustion vulnerability exists in ZIP archive processing. Orthanc automatically extracts ZIP archives uploaded to certain endpoints and trusts metadata fields describing the uncompressed size of archived files. An attacker can craft a small ZIP archive containing a forged size value, causing the server to allocate extremely large buffers during extraction.

debian
5 дней назад

A memory exhaustion vulnerability exists in ZIP archive processing. Or ...

EPSS

Процентиль: 4%
0.00017
Низкий