Resource exhaustion in Rubyzip - CVE-2019-16892
Published: February 10, 2020 / Updated: February 10, 2020
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to the data about the uncompressed size can be spoofed. A remote attacker can send a specially crafted ZIP file, bypass application checks on ZIP entry sizes, trigger resource exhaustion and perform a denial of service (DoS) attack.
Affected software
GitLab Enterprise Edition
openEuler
Fedora
rubygem-rubyzip
rubygem-rubyzip-doc
How to mitigate CVE-2019-16892
GitLab Enterprise Edition - addressed in versions 12.5.9, 12.6.6, 12.7.4
rubygem-rubyzip - addressed in versions 1.1.7-10.fc29, 1.1.7-10.fc30, 1.1.7-10.fc31
rubygem-rubyzip - update to 2.0.0-1
rubygem-rubyzip-doc - update to 2.0.0-1
External References
- https://github.com/rubyzip/rubyzip/pull/403
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/J45KSFPP6DFVWLC7Z73L7SX735CKZYO6/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/MWWPORMSBHZTMP4PGF4DQD22TTKBQMMC/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/X255K6ZBAQC462PQN2ND5HOTTQEJ2G2X/