In Keylime before 6.3.0, quote responses from the agent can contain possibly untrusted ZIP data which can lead to zip bombs.
The product does not properly control the allocation and maintenance of a limited resource.
Link | Tags |
---|---|
https://seclists.org/oss-sec/2022/q1/101 | third party advisory exploit patch mailing list |
https://github.com/keylime/keylime/security/advisories/GHSA-6xx7-m45w-76m2 | third party advisory |
https://github.com/keylime/keylime/commit/6e44758b64b0ee13564fc46e807f4ba98091c355 | third party advisory patch |