Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-6cmv-pvcc-pf5h

Опубликовано: 09 апр. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

A memory exhaustion vulnerability exists in ZIP archive processing. Orthanc automatically extracts ZIP archives uploaded to certain endpoints and trusts metadata fields describing the uncompressed size of archived files. An attacker can craft a small ZIP archive containing a forged size value, causing the server to allocate extremely large buffers during extraction.

A memory exhaustion vulnerability exists in ZIP archive processing. Orthanc automatically extracts ZIP archives uploaded to certain endpoints and trusts metadata fields describing the uncompressed size of archived files. An attacker can craft a small ZIP archive containing a forged size value, causing the server to allocate extremely large buffers during extraction.

EPSS

Процентиль: 34%
0.00426
Низкий

7.5 High

CVSS3

Дефекты

CWE-770

Связанные уязвимости

CVSS3: 7.5
ubuntu
4 месяца назад

A memory exhaustion vulnerability exists in ZIP archive processing. Orthanc automatically extracts ZIP archives uploaded to certain endpoints and trusts metadata fields describing the uncompressed size of archived files. An attacker can craft a small ZIP archive containing a forged size value, causing the server to allocate extremely large buffers during extraction.

CVSS3: 7.5
nvd
4 месяца назад

A memory exhaustion vulnerability exists in ZIP archive processing. Orthanc automatically extracts ZIP archives uploaded to certain endpoints and trusts metadata fields describing the uncompressed size of archived files. An attacker can craft a small ZIP archive containing a forged size value, causing the server to allocate extremely large buffers during extraction.

CVSS3: 7.5
debian
4 месяца назад

A memory exhaustion vulnerability exists in ZIP archive processing. Or ...

EPSS

Процентиль: 34%
0.00426
Низкий

7.5 High

CVSS3

Дефекты

CWE-770