rubyzip Project rubyzip 1.2.4 for Ruby

CPE Details

rubyzip Project rubyzip 1.2.4 for Ruby
1.2.4
2020-05-14
10h31 +00:00
2020-05-14
10h31 +00:00
Alerte pour un CPE
Restez informé de toutes modifications pour un CPE spécifique.
Gestion des notifications

CPE Name: cpe:2.3:a:rubyzip_project:rubyzip:1.2.4:*:*:*:*:ruby:*:*

Informations

Vendor

rubyzip_project

Product

rubyzip

Version

1.2.4

Target Software

ruby

Related CVE

Open and find in CVE List

CVE ID Publié Description Score Gravité
CVE-2019-16892 2019-09-24 22h00 +00:00 In Rubyzip before 1.3.0, a crafted ZIP file can bypass application checks on ZIP entry sizes because data about the uncompressed size can be spoofed. This allows attackers to cause a denial of service (disk consumption).
5.5
Moyen