adm-zip 0.5.14 through 0.6.0 Denial of Service via Zero Declared Uncompressed Size
21Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 8.7epss 0.4%
exploitation probability
0.4%top 67% of all CVEs
observed exploitation
nono source reports it
adm-zip versions 0.5.14 through 0.6.0 fail to apply zlib decompression output limits when ZIP entries declare zero uncompressed size. Attackers can craft malicious ZIP archives with highly compressible entries declaring zero size to exhaust memory and cause denial of service.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Affected products
cthackers · adm-zipReferences
https://github.com/cthackers/adm-ziphttps://github.com/cthackers/adm-zip/blob/v0.6.0/methods/inflater.jshttps://github.com/cthackers/adm-zip/commit/491600683dacb6cb9fe0718a0eeb9cb5eb49afa6https://github.com/cthackers/adm-zip/commit/8bc411184de1b5ca28138c53074fb61119994ddehttps://github.com/cthackers/adm-zip/security/advisories/GHSA-rcw4-f5rp-g42vhttps://www.vulncheck.com/advisories/adm-zip-0.5.14-through-0.6.0-denial-of-service-via-zero-declared-uncompressed-size