#VU25104 Resource exhaustion in Rubyzip - CVE-2019-16892
Published: February 10, 2020 / Updated: February 10, 2020
Rubyzip
Rubyzip
Description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to the data about the uncompressed size can be spoofed. A remote attacker can send a specially crafted ZIP file, bypass application checks on ZIP entry sizes, trigger resource exhaustion and perform a denial of service (DoS) attack.
Remediation
External links
- https://github.com/rubyzip/rubyzip/pull/403
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/J45KSFPP6DFVWLC7Z73L7SX735CKZYO6/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/MWWPORMSBHZTMP4PGF4DQD22TTKBQMMC/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/X255K6ZBAQC462PQN2ND5HOTTQEJ2G2X/