Vulnerability Name: | CVE-2019-13232 (CCN-166873) | ||||||||||||||||||||||||||||
Assigned: | 2018-10-16 | ||||||||||||||||||||||||||||
Published: | 2018-10-16 | ||||||||||||||||||||||||||||
Updated: | 2020-06-16 | ||||||||||||||||||||||||||||
Summary: | Info-ZIP UnZip 6.0 mishandles the overlapping of files inside a ZIP container, leading to denial of service (resource consumption), aka a "better zip bomb" issue. | ||||||||||||||||||||||||||||
CVSS v3 Severity: | 3.3 Low (CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L) 2.9 Low (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:U/RL:U/RC:R)
2.9 Low (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L/E:U/RL:U/RC:R)
3.5 Low (REDHAT Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:U/RL:U/RC:R)
| ||||||||||||||||||||||||||||
CVSS v2 Severity: | 2.1 Low (CVSS v2 Vector: AV:L/AC:L/Au:N/C:N/I:N/A:P)
| ||||||||||||||||||||||||||||
Vulnerability Type: | CWE-400 | ||||||||||||||||||||||||||||
Vulnerability Consequences: | Denial of Service | ||||||||||||||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2019-13232 Source: XF Type: UNKNOWN infozip-cve201913232-dos(166873) Source: MISC Type: Product, Release Notes, Third Party Advisory https://github.com/madler/unzip Source: CCN Type: Info-ZIP Web site Info-ZIP Home Page Source: MLIST Type: Mailing List, Third Party Advisory [debian-lts-announce] 20190707 [SECURITY] [DLA 1846-1] unzip security update Source: MLIST Type: Third Party Advisory [debian-lts-announce] 20190728 [SECURITY] [DLA 1846-2] unzip regression update Source: GENTOO Type: Third Party Advisory GLSA-202003-58 Source: CCN Type: NetApp Advisory Number NTAP-20190814-0002 CVE-2019-13232 Info-ZIP UnZip Vulnerability in NetApp Products Source: CONFIRM Type: Third Party Advisory https://security.netapp.com/advisory/ntap-20190814-0002/ Source: CONFIRM Type: Third Party Advisory https://support.f5.com/csp/article/K80311892?utm_source=f5support&utm_medium=RSS Source: MISC Type: Third Party Advisory https://www.bamsoftware.com/hacks/zipbomb/ Source: CCN Type: IBM Security Bulletin 6198772 (MQ Appliance) IBM MQ Appliance is affected by a denial of service vulnerability (CVE-2019-13232) Source: CCN Type: IBM Security Bulletin 6238168 (QRadar Network Security) IBM QRadar Network Security is affected by multiple vulnerabilities Source: CCN Type: IBM Security Bulletin 6342859 (DataPower Gateway) IBM DataPower Gateway may allow a potential DoS when importing malicious ZIP files (CVE-2019-13232) Source: CCN Type: IBM Security Bulletin 6347610 (QRadar SIEM) Unzip as used by IBM QRadar SIEM is vulnerable to denial of service (CVE-2019-13232) | ||||||||||||||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration 2: Configuration RedHat 1: Configuration RedHat 2: Configuration RedHat 3: Configuration RedHat 4: Configuration RedHat 5: Configuration RedHat 6: Configuration RedHat 7: Configuration CCN 1: ![]() | ||||||||||||||||||||||||||||
Oval Definitions | |||||||||||||||||||||||||||||
| |||||||||||||||||||||||||||||
BACK |