PT-2026-73062 · Pandora · Pandora
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
Pandora (affected versions not specified)
Description
Pandora contains a denial-of-service issue in its handling of DAA (Direct Access Archive) files. During the extraction of an internal ISO image from a DAA archive, the system uses the
zlib.decompress() function to process compressed chunks without enforcing a limit on the resulting uncompressed data. An attacker can submit a crafted DAA file containing highly compressed data, causing the system to expand a small input into an excessively large amount of data in memory. This process can lead to extreme memory consumption and CPU exhaustion, which may cause the extraction worker to become unresponsive or terminate, impacting the overall availability of the service. This type of attack is known as a decompression bomb, where a small file is designed to consume vast amounts of system resources upon decompression.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
DoS
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Pandora