PT-2022-19238 · Ireader+9 · Reader+9

·

CVE-2022-2879

·

Publicado

2022-10-04

·

Atualizado

2024-09-25

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Nome do software vulnerável e versões afetadas
Reader (versões afetadas não especificadas)
Descrição
O problema está relacionado ao fato de a função Reader.Read não definir um limite para o tamanho máximo dos cabeçalhos de arquivo. Um arquivo compactado criado de forma maliciosa poderia fazer com que a função Reader.Read alocasse quantidades ilimitadas de memória, causando potencialmente esgotamento de recursos ou falhas do sistema. Após a correção, a função Reader.Read limita o tamanho máximo dos blocos de cabeçalho a 1 MiB.
Recomendações
No momento, não há informações sobre uma versão mais recente que contenha uma correção para essa vulnerabilidade.

Exploit

DoS

Allocation of Resources Without Limits

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALSA-2023:0328
ALSA-2023:0446
ALSA-2023:2204
ALSA-2023:2780
ALSA-2024:0121
ALT-PU-2022-2743
ALT-PU-2022-2873
ALT-PU-2023-1205
AZL-11128
AZL-37526
AZL-41393
AZL-41765
AZL-41786
AZL-41787
AZL-41901
AZL-44052
AZL-44091
AZL-44523
AZL-79006
BIT-GOLANG-2022-2879
CESA-2023_0446
CESA-2023_2780
CESA-2024_0121
CESA-2024_2988
CVE-2022-2879
GO-2022-1037
INFSA-2024_2988
MGASA-2022-0377
OESA-2022-2004
OPENSUSE-SU-2022_3668-1
OPENSUSE-SU-2022_3669-1
OPENSUSE-SU-2024:12391-1
OPENSUSE-SU-2024:12392-1
OPENSUSE-SU-2024:12421-1
RHSA-2022:7398
RHSA-2023:0328
RHSA-2023:0445
RHSA-2023:0446
RHSA-2023:0708
RHSA-2023:0727
RHSA-2023:2204
RHSA-2023:2780
RHSA-2023:3613
RHSA-2023:4003
RHSA-2023_0328
RHSA-2023_0446
RHSA-2023_2204
RHSA-2023_2780
RHSA-2024:0121
RHSA-2024:2988
RHSA-2024_0121
RHSA-2024_2988
RLSA-2023:0328
RLSA-2023:0446
SUSE-SU-2022:3668-1
SUSE-SU-2022:3669-1
SUSE-SU-2022_3668-1
SUSE-SU-2022_3669-1
SUSE-SU-2023:2312-1
USN-6038-1
USN-6038-2

Produtos afetados

Alt Linux
Almalinux
Centos
Debian
Linuxmint
Reader
Red Hat
Rocky Linux
Suse
Ubuntu