Vulnerability GHSA-5m2v-hc64-56h6
Medium Risk
MEDIUM RISK
CVSS Score: 5.5
Score Range: 4.0–6.9
Medium severity vulnerabilities (CVSS 4.0–6.9). Important issues that meaningfully reduce security confidence.
6 years ago
September 30, 2019 at 04:05 PM UTC
Rubyzip denial of service
0.5.7 - 1.2.4
0.5.7 - 1.2.4
Summary
Rubyzip denial of service
Details
In Rubyzip before 1.3.0, a crafted ZIP file can bypass application checks on ZIP entry sizes because data about the uncompressed size can be spoofed. This allows attackers to cause a denial of service (disk consumption).
References
- ADVISORY — nvd.nist.gov
- WEB — github.com
- WEB — github.com
- WEB — access.redhat.com
- WEB — access.redhat.com
- WEB — github.com
- WEB — github.com
- PACKAGE — github.com
- WEB — lists.fedoraproject.org
- WEB — lists.fedoraproject.org
- WEB — lists.fedoraproject.org
- WEB — lists.fedoraproject.org
- WEB — lists.fedoraproject.org
- WEB — lists.fedoraproject.org
Related Vulnerabilities
Other vulnerabilities affecting the same packages
High Risk
24 days ago
rubyzip path traversal vulnerability
0.5.7 - 3.3.1 GHSA-47m2-wp7j-p9vc
0.5.7 - 3.3.1 GHSA-47m2-wp7j-p9vc
Critical
8 years ago
Rubyzip gem contains a Directory Traversal vulnerability in zip file component
0.5.7 - 1.2.1 GHSA-vqcq-mrmw-mcmg
0.5.7 - 1.2.1 GHSA-vqcq-mrmw-mcmg
Critical
8 years ago
Directory traversal vulnerability in RubyZip
0.5.7 - 1.2.0 GHSA-gcqq-w6gr-h9j9
0.5.7 - 1.2.0 GHSA-gcqq-w6gr-h9j9
Impacted packages
Timeline
Published
6 years ago
September 30, 2019 at 04:05 PM UTC
Fixed (1.3.0)
7 years ago
September 25, 2019 at 07:38 PM UTC
Last Modified
2 years ago
February 16, 2024 at 08:20 AM UTC