Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2017-16129

Опубликовано: 07 июн. 2018
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 7.1
CVSS3: 5.9

Описание

The HTTP client module superagent is vulnerable to ZIP bomb attacks. In a ZIP bomb attack, the HTTP server replies with a compressed response that becomes several magnitudes larger once uncompressed. If a client does not take special care when processing such responses, it may result in excessive CPU and/or memory consumption. An attacker might exploit such a weakness for a DoS attack. To exploit this the attacker must control the location (URL) that superagent makes a request to.

РелизСтатусПримечание
bionic

ignored

end of standard support, was needed
devel

not-affected

esm-apps/bionic

needed

esm-apps/focal

not-affected

5.2.2-1
esm-apps/jammy

not-affected

esm-apps/noble

not-affected

esm-apps/xenial

needed

esm-infra-legacy/trusty

DNE

focal

not-affected

5.2.2-1
groovy

not-affected

Показывать по

EPSS

Процентиль: 59%
0.00385
Низкий

7.1 High

CVSS2

5.9 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.9
nvd
больше 7 лет назад

The HTTP client module superagent is vulnerable to ZIP bomb attacks. In a ZIP bomb attack, the HTTP server replies with a compressed response that becomes several magnitudes larger once uncompressed. If a client does not take special care when processing such responses, it may result in excessive CPU and/or memory consumption. An attacker might exploit such a weakness for a DoS attack. To exploit this the attacker must control the location (URL) that superagent makes a request to.

CVSS3: 5.9
debian
больше 7 лет назад

The HTTP client module superagent is vulnerable to ZIP bomb attacks. I ...

CVSS3: 5.9
github
больше 7 лет назад

superagent vulnerable to zip bomb attacks

EPSS

Процентиль: 59%
0.00385
Низкий

7.1 High

CVSS2

5.9 Medium

CVSS3