Candidate: CVE-2019-16892 PublicDate: 2019-09-25 22:15:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-16892 https://github.com/rubyzip/rubyzip/pull/403 https://github.com/rubyzip/rubyzip/commit/4167f0ce67e42b082605bca75c7bdfd01eb23804 https://github.com/rubyzip/rubyzip/commit/7849f7362ab0cd23d5730ef8b6f2c39252da2285 https://github.com/rubyzip/rubyzip/commit/97cb6aefe6d12bd2429d7a2e119ccb26f259d71d Description: In Rubyzip before 1.3.0, a crafted ZIP file can bypass application checks on ZIP entry sizes because data about the uncompressed size can be spoofed. This allows attackers to cause a denial of service (disk consumption). Ubuntu-Description: Notes: Mitigation: Bugs: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=941222 Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H [5.5 MEDIUM] Patches_ruby-zip: upstream_ruby-zip: needs-triage precise/esm_ruby-zip: DNE trusty_ruby-zip: ignored (out of standard support) trusty/esm_ruby-zip: DNE xenial_ruby-zip: ignored (end of standard support, was needed) bionic_ruby-zip: needed disco_ruby-zip: ignored (reached end-of-life) eoan_ruby-zip: ignored (reached end-of-life) focal_ruby-zip: not-affected (2.0.0-2) groovy_ruby-zip: not-affected (2.0.0-2) hirsute_ruby-zip: not-affected (2.0.0-2) impish_ruby-zip: not-affected (2.0.0-2) jammy_ruby-zip: not-affected (2.0.0-2) devel_ruby-zip: not-affected (2.0.0-2)