Skip to content

Extractor module vulnerable to ZIP bomb

Moderate
Rafiot published GHSA-pc3j-vcjp-8rhv Jan 10, 2023

Package

No package listed

Affected versions

<= v1.3.0

Patched versions

v1.3.1

Description

Impact

If a zib bomb is submitted to Pandora, it may result in a DOS.

Patches

Better handling of recursive archives and cut-off point.

Workarounds

Disable extractor.

References

Patch: Commit

Severity

Moderate

CVE ID

CVE-2023-22898

Weaknesses

No CWEs