Описание
Redlib is an alternative private front-end to Reddit. A vulnerability has been identified in Redlib where an attacker can cause a denial-of-service (DOS) condition by submitting a specially crafted base2048-encoded DEFLATE decompression bomb to the restore_preferences form. This leads to excessive memory consumption and potential system instability, which can be exploited to disrupt Redlib instances. This vulnerability is fixed in 0.36.0.
Уязвимые конфигурации
Конфигурация 1Версия до 0.36.0 (исключая)
cpe:2.3:a:redlib:redlib:*:*:*:*:*:*:*:*
EPSS
Процентиль: 64%
0.00466
Низкий
7.5 High
CVSS3
Дефекты
CWE-400
Связанные уязвимости
github
11 месяцев назад
Redlib allows a Denial of Service via DEFLATE Decompression Bomb in restore_preferences Form
EPSS
Процентиль: 64%
0.00466
Низкий
7.5 High
CVSS3
Дефекты
CWE-400