In Keylime before 6.3.0, quote responses from the agent can contain possibly untrusted ZIP data which can lead to zip bombs.
The product does not properly control the allocation and maintenance of a limited resource.
Link | Tags |
---|---|
https://seclists.org/oss-sec/2022/q1/101 | exploit mailing list patch third party advisory |
https://github.com/keylime/keylime/security/advisories/GHSA-6xx7-m45w-76m2 | third party advisory |
https://github.com/keylime/keylime/commit/6e44758b64b0ee13564fc46e807f4ba98091c355 | patch third party advisory |