Vulnerability Bulletins

MSA-20-0014: Denial of service risk in file picker unzip functionality


System information

   
Affected software PHP

Description

by Michael Hawkins. The decompressed size of zip files was not checked against available user quota before unzipping them, which could lead to a denial of service risk.Severity/Risk:SeriousVersions affected:3.9 to 3.9.1, 3.8 to 3.8.4, 3.7 to 3.7.7, 3.5 to 3.5.13 and earlier unsupported versionsVersions fixed:3.9.2, 3.8.5, 3.7.8 and 3.5.14Reported by:Ivan NovichkovCVE identifier:CVE-2020-25630Changes

More info:

https://moodle.org/mod/forum/discuss.php?d=410842&parent=1657004

Standar resources

Property Value
CVE CVE-2020-25630.

Version history

Version Comments Date
1.0 Advisory issued 2020-09-25
Ministerio de Defensa
CNI
CCN
CCN-CERT