Lucene search

K
redhatcveRedhat.comRH:CVE-2019-16892
HistoryNov 12, 2019 - 7:07 a.m.

CVE-2019-16892

2019-11-1207:07:20
redhat.com
access.redhat.com
12

0.001 Low

EPSS

Percentile

47.2%

A vulnerability in Rubyzip, versions prior to 1.3.0, allows a crafted ZIP file to bypass application checks on ZIP entry sizes. This allows an attacker to spoof data regarding the uncompressed size of the ZIP file, causing a denial of service due to disk consumption. Availability of the system is the highest threat.