IO::Uncompress::Unzip versions before 2.220 for Perl allow CPU exhaustion via per-byte read loop in fastForward. fastForward() compares length $offset (the digit count of the offset, 1 to 19) against the chunk size $c instead of $offset itself, so $c shrinks from 16 KiB to 1-19 bytes per iteration. Extracting a named entry from an attacker supplied zip via IO::Uncompress::Unzip->new($zip, Name => $target) drives a per-byte read loop scaling with the entry's compressed size, up to the non-Zip64 4 GiB cap.
| Vendor | Product | Versions |
|---|---|---|
| graham ollis | io::uncompress::unzip | 0 |
Downstream vendors/products affected by this vulnerability
| Vendor | Product | Source | Confidence |
|---|---|---|---|
| ibm | vios | cert_advisory | 90% |
| ibm | aix | cert_advisory | 90% |
Updated affected versions to include 2.219, changed severity to MEDIUM, and noted no patch available.
Updated product name to IO-Compress, changed severity to HIGH, and marked exploit availability and active exploitation as true.
Initial creation