Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:21575
HistorySep 26, 2019 - 1:19 a.m.

Denial Of Service (DoS)

2019-09-2601:19:39
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
11

0.001 Low

EPSS

Percentile

47.2%

Rubyzip is vulnerable to denial of service (DoS) attacks. The zip file entry extract method does not check or limit the file size at the time of extraction, allowing attackers to provide malicious ZIP file entries (aka) ZIP Bomb with spoofed uncompressed sizes to consume disk space at the time of extraction.

CPENameOperatorVersion
rubyziple1.2.4