CVE-2019-16892: Medium severity Rubyzip Project Rubyzip vulnerability
A vulnerability was found in Rubyzip before 1.3.0, a crafted ZIP file can bypass application checks on ZIP entry sizes because data about the uncompressed size can be spoofed. This allows attackers to cause a denial of service (disk consumption).
Reference: https://github.com/rubyzip/rubyzip/pull/403
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
rubygems/rubyzipto a version that resolves this vulnerability.Fixed in 1.3.0 - Upgrade
Upgrade
redhat/Rubyzipto a version that resolves this vulnerability.Fixed in 1.3.0 - Upgrade
Upgrade
Rubyzipto a version that resolves this vulnerability.Fixed in 1.3.0
Event History
Frequently Asked Questions
What is the vulnerability ID of this issue?
The vulnerability ID of this issue is CVE-2019-16892.
What is the severity of CVE-2019-16892?
The severity of CVE-2019-16892 is high.
How does CVE-2019-16892 affect Rubyzip?
CVE-2019-16892 affects Rubyzip versions before 1.3.0.
What is the impact of CVE-2019-16892?
The impact of CVE-2019-16892 is a denial of service (disk consumption).
How can I fix CVE-2019-16892?
To fix CVE-2019-16892, update Rubyzip to version 1.3.0 or later.