Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[C/C++]: DOS through Decompression #779

Open
1 of 2 tasks
am0o0 opened this issue Jul 31, 2023 · 3 comments
Open
1 of 2 tasks

[C/C++]: DOS through Decompression #779

am0o0 opened this issue Jul 31, 2023 · 3 comments
Assignees
Labels
All For One Submissions to the All for One, One for All bounty

Comments

@am0o0
Copy link

am0o0 commented Jul 31, 2023

Query PR

github/codeql#13560

Language

C/C++

CVE(s) ID list

CWE

No response

Report

Extracting Compressed files with any compression algorithm like gzip can cause to denial of service attacks. Attackers can compress a huge file which created by repeated similar byte and convert it to a small compressed file.

Are you planning to discuss this vulnerability submission publicly? (Blog Post, social networks, etc).

  • Yes
  • No

Blog post link

No response

@am0o0 am0o0 added the All For One Submissions to the All for One, One for All bounty label Jul 31, 2023
@Kwstubbs Kwstubbs self-assigned this Aug 7, 2023
@Kwstubbs
Copy link

@amammad could I get a database for one of these CVES? thanks

@Kwstubbs
Copy link

Kwstubbs commented May 31, 2024

@am0o0 pinging for CodeQL database so I start scoring

@ghsecuritylab
Copy link
Collaborator

Your submission is now in status Query review.

For information, the evaluation workflow is the following:
Initial triage > Test run > Results analysis > Query review > Final decision > Pay > Closed

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
All For One Submissions to the All for One, One for All bounty
Projects
None yet
Development

No branches or pull requests

3 participants