CVE-2019-16892
published 2019-09-25CVE-2019-16892: In Rubyzip before 1.3.0, a crafted ZIP file can bypass application checks on ZIP entry sizes because data about the uncompressed size can be spoofed. This…
PriorityP419medium5.5CVSS 3.1
AVLACLPRNUIRSUCNINAH
EPSS
1.58%
72.8th percentile
In Rubyzip before 1.3.0, a crafted ZIP file can bypass application checks on ZIP entry sizes because data about the uncompressed size can be spoofed. This allows attackers to cause a denial of service (disk consumption).
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | ruby-zip | < ruby-zip 2.0.0-1 (bookworm) | ruby-zip 2.0.0-1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| redhat | cloudforms | — | — |
| redhat | cloudforms | — | — |
| rubyzip_project | rubyzip | < 1.3.0 | 1.3.0 |
| rubyzip_project | rubyzip | >= 0 < 1.3.0 | 1.3.0 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
nvdv2.07.1HIGHAV:N/AC:M/Au:N/C:N/I:N/A:C
osv5.5MEDIUM
vendor_debian5.5LOW
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Rubyzip denial of service
osv·2019-09-30
CVE-2019-16892 [MEDIUM] Rubyzip denial of service
Rubyzip denial of service
In Rubyzip before 1.3.0, a crafted ZIP file can bypass application checks on ZIP entry sizes because data about the uncompressed size can be spoofed. This allows attackers to cause a denial of service (disk consumption).
GHSA
Rubyzip denial of service
ghsa·2019-09-30
CVE-2019-16892 [MEDIUM] CWE-400 Rubyzip denial of service
Rubyzip denial of service
In Rubyzip before 1.3.0, a crafted ZIP file can bypass application checks on ZIP entry sizes because data about the uncompressed size can be spoofed. This allows attackers to cause a denial of service (disk consumption).
OSV
CVE-2019-16892: In Rubyzip before 1
osv·2019-09-25·CVSS 5.5
CVE-2019-16892 [MEDIUM] CVE-2019-16892: In Rubyzip before 1
In Rubyzip before 1.3.0, a crafted ZIP file can bypass application checks on ZIP entry sizes because data about the uncompressed size can be spoofed. This allows attackers to cause a denial of service (disk consumption).
Red Hat
cfme: rubygem-rubyzip denial of service via crafted ZIP file
vendor_redhat·2019-09-25·CVSS 5.5
CVE-2019-16892 [MEDIUM] CWE-400 cfme: rubygem-rubyzip denial of service via crafted ZIP file
cfme: rubygem-rubyzip denial of service via crafted ZIP file
In Rubyzip before 1.3.0, a crafted ZIP file can bypass application checks on ZIP entry sizes because data about the uncompressed size can be spoofed. This allows attackers to cause a denial of service (disk consumption).
A vulnerability in Rubyzip, versions prior to 1.3.0, allows a crafted ZIP file to bypass application checks on ZIP entry sizes. This allows an attacker to spoof data regarding the uncompressed size of the ZIP file, causing a denial of service due to disk consumption. Availability of the system is the highest threat.
Statement: Red Hat CloudForms 4.7 (5.10.13) release is affected, but not vulnerable as they include fixes for Rubyzip version 1.3.0. This issue was fixed in RHBA-2019:4047 (https://access.redhat.co
Debian
CVE-2019-16892: ruby-zip - In Rubyzip before 1.3.0, a crafted ZIP file can bypass application checks on ZIP...
vendor_debian·2019·CVSS 5.5
CVE-2019-16892 [MEDIUM] CVE-2019-16892: ruby-zip - In Rubyzip before 1.3.0, a crafted ZIP file can bypass application checks on ZIP...
In Rubyzip before 1.3.0, a crafted ZIP file can bypass application checks on ZIP entry sizes because data about the uncompressed size can be spoofed. This allows attackers to cause a denial of service (disk consumption).
Scope: local
bookworm: resolved (fixed in 2.0.0-1)
bullseye: resolved (fixed in 2.0.0-1)
forky: resolved (fixed in 2.0.0-1)
sid: resolved (fixed in 2.0.0-1)
trixie: resolved (fixed in 2.0.0-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-16892 rubygem-rubyzip: denial of service via crafted ZIP file [fedora-all]
bugzilla·2019-11-12·CVSS 5.5
CVE-2019-16892 [MEDIUM] CVE-2019-16892 rubygem-rubyzip: denial of service via crafted ZIP file [fedora-all]
CVE-2019-16892 rubygem-rubyzip: denial of service via crafted ZIP file [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported ve
Bugzilla
CVE-2019-16892 cfme: rubygem-rubyzip denial of service via crafted ZIP file
bugzilla·2019-11-12·CVSS 5.5
CVE-2019-16892 [MEDIUM] CVE-2019-16892 cfme: rubygem-rubyzip denial of service via crafted ZIP file
CVE-2019-16892 cfme: rubygem-rubyzip denial of service via crafted ZIP file
A vulnerability was found in Rubyzip before 1.3.0, a crafted ZIP file can bypass application checks on ZIP entry sizes because data about the uncompressed size can be spoofed. This allows attackers to cause a denial of service (disk consumption).
Reference:
https://github.com/rubyzip/rubyzip/pull/403
Discussion:
Created rubygem-rubyzip tracking bugs for this issue:
Affects: fedora-all [bug 1771299]
---
Statement:
Red Hat CloudForms 4.7 (5.10.13) release is affected, but not vulnerable as they include fixes for Rubyzip version 1.3.0. This issue was fixed in RHBA-2019:4047 (https://access.redhat.com/errata/RHBA-2019:4047) as part of CFME component.
---
This issue has been addressed in the following products
https://access.redhat.com/errata/RHBA-2019:4047https://access.redhat.com/errata/RHSA-2019:4201https://github.com/rubyzip/rubyzip/commit/d65fe7bd283ec94f9d6dc7605f61a6b0dd00f55ehttps://github.com/rubyzip/rubyzip/pull/403https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/J45KSFPP6DFVWLC7Z73L7SX735CKZYO6/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MWWPORMSBHZTMP4PGF4DQD22TTKBQMMC/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/X255K6ZBAQC462PQN2ND5HOTTQEJ2G2X/https://access.redhat.com/errata/RHBA-2019:4047https://access.redhat.com/errata/RHSA-2019:4201https://github.com/rubyzip/rubyzip/commit/d65fe7bd283ec94f9d6dc7605f61a6b0dd00f55ehttps://github.com/rubyzip/rubyzip/pull/403https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/J45KSFPP6DFVWLC7Z73L7SX735CKZYO6/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MWWPORMSBHZTMP4PGF4DQD22TTKBQMMC/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/X255K6ZBAQC462PQN2ND5HOTTQEJ2G2X/
2019-09-25
Published