Логотип exploitDog
bind:CVE-2025-46730
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-46730

Количество 2

Количество 2

nvd логотип

CVE-2025-46730

9 месяцев назад

MobSF is a mobile application security testing tool used. Typically, MobSF is deployed on centralized internal or cloud-based servers that also host other security tools and web applications. Access to the MobSF web interface is often granted to internal security teams, audit teams, and external vendors. MobSF provides a feature that allows users to upload ZIP files for static analysis. Upon upload, these ZIP files are automatically extracted and stored within the MobSF directory. However, in versions up to and including 4.3.2, this functionality lacks a check on the total uncompressed size of the ZIP file, making it vulnerable to a ZIP of Death (zip bomb) attack. Due to the absence of safeguards against oversized extractions, an attacker can craft a specially prepared ZIP file that is small in compressed form but expands to a massive size upon extraction. Exploiting this, an attacker can exhaust the server's disk space, leading to a complete denial of service (DoS) not just for MobSF

CVSS3: 6.8
EPSS: Низкий
github логотип

GHSA-c5vg-26p8-q8cr

9 месяцев назад

Mobile Security Framework (MobSF) Allows Web Server Resource Exhaustion via ZIP of Death Attack

CVSS3: 6.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-46730

MobSF is a mobile application security testing tool used. Typically, MobSF is deployed on centralized internal or cloud-based servers that also host other security tools and web applications. Access to the MobSF web interface is often granted to internal security teams, audit teams, and external vendors. MobSF provides a feature that allows users to upload ZIP files for static analysis. Upon upload, these ZIP files are automatically extracted and stored within the MobSF directory. However, in versions up to and including 4.3.2, this functionality lacks a check on the total uncompressed size of the ZIP file, making it vulnerable to a ZIP of Death (zip bomb) attack. Due to the absence of safeguards against oversized extractions, an attacker can craft a specially prepared ZIP file that is small in compressed form but expands to a massive size upon extraction. Exploiting this, an attacker can exhaust the server's disk space, leading to a complete denial of service (DoS) not just for MobSF

CVSS3: 6.8
0%
Низкий
9 месяцев назад
github логотип
GHSA-c5vg-26p8-q8cr

Mobile Security Framework (MobSF) Allows Web Server Resource Exhaustion via ZIP of Death Attack

CVSS3: 6.8
0%
Низкий
9 месяцев назад

Уязвимостей на страницу