CVE-2023-22898: Input Validation
Published Jan 10, 2023
·Updated
workers/extractor.py in Pandora (aka pandora-analysis/pandora) 1.3.0 allows a denial of service when an attacker submits a deeply nested ZIP archive (aka ZIP bomb).
Affected Software
1 affected component
Circl Pandora<1.3.1
Remediation
Event History
Jan 10, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2023-22898?
CVE-2023-22898 has a severity rating of high due to its potential to cause denial of service through ZIP bomb attacks.
2
How does CVE-2023-22898 affect Pandora software?
CVE-2023-22898 allows attackers to exploit the file extraction process in Pandora, leading to service interruptions.
3
How do I fix CVE-2023-22898?
To fix CVE-2023-22898, update Pandora to version 1.3.1 or later, where the vulnerability has been addressed.
4
What versions of Pandora are affected by CVE-2023-22898?
Pandora versions prior to 1.3.1 are affected by CVE-2023-22898.
5
What is a ZIP bomb in the context of CVE-2023-22898?
A ZIP bomb is a malicious file that is designed to crash or significantly slow down file processing systems by using nested ZIP archives.