Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Memory Exhaustion via Forged ZIP Metadata
Vulnerability Description
A memory exhaustion vulnerability exists in ZIP archive processing. Orthanc automatically extracts ZIP archives uploaded to certain endpoints and trusts metadata fields describing the uncompressed size of archived files. An attacker can craft a small ZIP archive containing a forged size value, causing the server to allocate extremely large buffers during extraction.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Orthanc 安全漏洞
Vulnerability Description
Orthanc是Orthanc公司的一款免费的开源软件。 Orthanc存在安全漏洞,该漏洞源于处理ZIP存档时存在内存耗尽漏洞,可能导致服务器在提取期间分配极大的缓冲区。
CVSS Information
N/A
Vulnerability Type
N/A