In Rubyzip before 1.3.0, a crafted ZIP file can bypass application checks on ZIP entry sizes because data about the uncompressed size can be spoofed. This allows attackers to cause a denial of service (disk consumption).
References
Configurations
Information
Published : 2019-09-25 15:15
Updated : 2019-11-21 19:15
NVD link : CVE-2019-16892
Mitre link : CVE-2019-16892
JSON object : View
CWE
CWE-400
Uncontrolled Resource Consumption
Products Affected
rubyzip_project
- rubyzip