Lucene search

K
osvGoogleOSV:GHSA-5M2V-HC64-56H6
HistorySep 30, 2019 - 4:05 p.m.

Rubyzip denial of service

2019-09-3016:05:32
Google
osv.dev
11

0.001 Low

EPSS

Percentile

47.2%

In Rubyzip before 1.3.0, a crafted ZIP file can bypass application checks on ZIP entry sizes because data about the uncompressed size can be spoofed. This allows attackers to cause a denial of service (disk consumption).

References