Описание
In Rubyzip before 1.3.0, a crafted ZIP file can bypass application checks on ZIP entry sizes because data about the uncompressed size can be spoofed. This allows attackers to cause a denial of service (disk consumption).
Ссылки
- Third Party Advisory
- Third Party Advisory
- Patch
- ExploitIssue TrackingPatchThird Party Advisory
- Mailing List
- Mailing List
- Mailing List
- Third Party Advisory
- Third Party Advisory
- Patch
- ExploitIssue TrackingPatchThird Party Advisory
- Mailing List
- Mailing List
- Mailing List
Уязвимые конфигурации
Одно из
Одно из
EPSS
5.5 Medium
CVSS3
7.1 High
CVSS2
Дефекты
Связанные уязвимости
In Rubyzip before 1.3.0, a crafted ZIP file can bypass application checks on ZIP entry sizes because data about the uncompressed size can be spoofed. This allows attackers to cause a denial of service (disk consumption).
In Rubyzip before 1.3.0, a crafted ZIP file can bypass application checks on ZIP entry sizes because data about the uncompressed size can be spoofed. This allows attackers to cause a denial of service (disk consumption).
In Rubyzip before 1.3.0, a crafted ZIP file can bypass application che ...
EPSS
5.5 Medium
CVSS3
7.1 High
CVSS2