In Rubyzip before 1.3.0, a crafted ZIP file can bypass application checks on ZIP entry sizes because data about the uncompressed size can be spoofed. This allows attackers to cause a denial of service (disk consumption).
{
"nvd_published_at": "2019-09-25T22:15:10Z",
"github_reviewed": true,
"github_reviewed_at": "2019-09-30T16:04:36Z",
"severity": "MODERATE",
"cwe_ids": [
"CWE-400"
]
}