SB2020032673 - Resource exhaustion in unzip (Alpine package)
Published: March 26, 2020
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Resource exhaustion (CVE-ID: CVE-2019-13232)
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to application does not properly control consumption of internal resources. A remote attacker can trigger resource exhaustion and perform a denial of service (DoS) attack via a specially crafted zip file.
Remediation
Install update from vendor's website.
References
- https://git.alpinelinux.org/aports/commit/?id=2d5ea9b0ef18df74869bf77e2b9b7beda9a8cfe8
- https://git.alpinelinux.org/aports/commit/?id=55374a75a54b07b8c1d75d154dfc2524813d6f09
- https://git.alpinelinux.org/aports/commit/?id=8c7e0d5c8061d459c8b2b33b122206ec6fa59163
- https://git.alpinelinux.org/aports/commit/?id=91e40e209481a5c5d1d66f2d5b0d328bf5c28dff
- https://git.alpinelinux.org/aports/commit/?id=f9323c22d56bf68412789c47e0ba4b429feeea7f