cfme: rubygem-rubyzip denial of service via crafted ZIP file
Published Sep 25, 2019
5.5
MEDIUMCVSS 3.1
EPSS 1.58%
Description
In Rubyzip before 1.3.0, a crafted ZIP file can bypass application checks on ZIP entry sizes because data about the uncompressed size can be spoofed. This allows attackers to cause a denial of service (disk consumption).
Affected products
No data.
Configuration 1
- < 1.3.0
Configuration 2
- 29
- 30
- 31
Configuration 3
- 4.7
- 5.11
No data.
CloudForms Management Engine 5.10
cfme-0:5.10.13.1-1.el7cf
Fixed · RHBA-2019:4047
CloudForms Management Engine 5.10
cfme-amazon-smartstate-0:5.10.13.1-1.el7cf
Fixed · RHBA-2019:4047
CloudForms Management Engine 5.10
cfme-appliance-0:5.10.13.1-1.el7cf
Fixed · RHBA-2019:4047
CloudForms Management Engine 5.10
cfme-gemset-0:5.10.13.1-1.el7cf
Fixed · RHBA-2019:4047
CloudForms Management Engine 5.10
ruby-0:2.4.9-93.el7cf
Fixed · RHBA-2019:4047
CloudForms Management Engine 5.11
cfme-0:5.11.1.2-1.el8cf
Fixed · RHSA-2019:4201
CloudForms Management Engine 5.11
cfme-amazon-smartstate-0:5.11.1.2-1.el8cf
Fixed · RHSA-2019:4201
CloudForms Management Engine 5.11
cfme-appliance-0:5.11.1.2-1.el8cf
Fixed · RHSA-2019:4201
CloudForms Management Engine 5.11
cfme-gemset-0:5.11.1.2-1.el8cf
Fixed · RHSA-2019:4201
CloudForms Management Engine 5.11
ovirt-ansible-hosted-engine-setup-0:1.0.28-1.el8ev
Fixed · RHSA-2019:4201
CloudForms Management Engine 5.11
v2v-conversion-host-0:1.15.0-1.el8ev
Fixed · RHSA-2019:4201
| Product | Package | State | Advisory |
|---|---|---|---|
| CloudForms Management Engine 5.10 | cfme-0:5.10.13.1-1.el7cf | Fixed | RHBA-2019:4047 |
| CloudForms Management Engine 5.10 | cfme-amazon-smartstate-0:5.10.13.1-1.el7cf | Fixed | RHBA-2019:4047 |
| CloudForms Management Engine 5.10 | cfme-appliance-0:5.10.13.1-1.el7cf | Fixed | RHBA-2019:4047 |
| CloudForms Management Engine 5.10 | cfme-gemset-0:5.10.13.1-1.el7cf | Fixed | RHBA-2019:4047 |
| CloudForms Management Engine 5.10 | ruby-0:2.4.9-93.el7cf | Fixed | RHBA-2019:4047 |
| CloudForms Management Engine 5.11 | cfme-0:5.11.1.2-1.el8cf | Fixed | RHSA-2019:4201 |
| CloudForms Management Engine 5.11 | cfme-amazon-smartstate-0:5.11.1.2-1.el8cf | Fixed | RHSA-2019:4201 |
| CloudForms Management Engine 5.11 | cfme-appliance-0:5.11.1.2-1.el8cf | Fixed | RHSA-2019:4201 |
| CloudForms Management Engine 5.11 | cfme-gemset-0:5.11.1.2-1.el8cf | Fixed | RHSA-2019:4201 |
| CloudForms Management Engine 5.11 | ovirt-ansible-hosted-engine-setup-0:1.0.28-1.el8ev | Fixed | RHSA-2019:4201 |
| CloudForms Management Engine 5.11 | v2v-conversion-host-0:1.15.0-1.el8ev | Fixed | RHSA-2019:4201 |
No package ranges for this CVE.
Remediation
Red Hat statement
Red Hat CloudForms 4.7 (5.10.13) release is affected, but not vulnerable as they include fixes for Rubyzip version 1.3.0. This issue was fixed in RHBA-2019:4047 (https://access.redhat.com/errata/RHBA-2019:4047) as part of CFME component.
References (17)
- https://access.redhat.com/errata/RHBA-2019:4047 vendor-advisoryThird Party Advisory
- https://access.redhat.com/errata/RHSA-2019:4201 vendor-advisoryThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2019-16892 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1771298 Issue Tracking
- https://github.com/advisories/GHSA-5m2v-hc64-56h6 Advisory
- https://github.com/jdleesmiller/ruby-advisory-db/blob/master/gems/rubyzip/CVE-2019-16892.yml
- https://github.com/rubysec/ruby-advisory-db/blob/master/gems/rubyzip/CVE-2019-16892.yml
- https://github.com/rubyzip/rubyzip/commit/d65fe7bd283ec94f9d6dc7605f61a6b0dd00f55e Patch
- https://github.com/rubyzip/rubyzip/pull/403 ExploitIssue TrackingPatchThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/J45KSFPP6DFVWLC7Z73L7SX735CKZYO6/ vendor-advisoryMailing List
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MWWPORMSBHZTMP4PGF4DQD22TTKBQMMC/ vendor-advisoryMailing List
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/X255K6ZBAQC462PQN2ND5HOTTQEJ2G2X/ vendor-advisoryMailing List
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/J45KSFPP6DFVWLC7Z73L7SX735CKZYO6/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/MWWPORMSBHZTMP4PGF4DQD22TTKBQMMC/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/X255K6ZBAQC462PQN2ND5HOTTQEJ2G2X/
- https://nvd.nist.gov/vuln/detail/CVE-2019-16892
- https://www.cve.org/CVERecord?id=CVE-2019-16892
Change history (0)
No recorded changes yet.