redlib
Activity
- Latest release
- 1y ago
- Total releases
- 8
- Cadence
- ~6 days
- Last 12 months
- 0
Details
- License
- AGPL-3.0-only
- First release
- Dec 27, 2023
| Version | Released | |
|---|---|---|
0.36.0
unknown
|
0.36.0
unknown
Dependencies (42)
+ 34 more |
|
0.35.1
unknown
1 CVE
CVE-2025-30160
GHSA-g8vq-v3mg-7mrg
Mar 21, 2025
Redlib allows a Denial of Service via DEFLATE Decompression Bomb in restore_preferences Form
High
Network
Low
None
None
A vulnerability has been identified in Redlib where an attacker can cause a denial-of-service (DOS) condition by submitting a specially crafted base2048-encoded DEFLATE decompression bomb to the restore_preferences form. This leads to excessive memory consumption and potential system instability, which can be exploited to disrupt Redlib instances. This vulnerability was introduced in 2e95e1fc6e2064ccfae87964b4860bda55eddb9a and fixed in 15147cea8e42f6569a11603d661d71122f6a02dc. ImpactWhat kind of vulnerability is it? Who is impacted? This vulnerability allows a remote attacker with network access to exploit the preference restoration mechanism by providing a compressed payload that expands dramatically upon decompression. The issue arises because the system automatically decompresses user-supplied data without enforcing size limits, potentially leading to:
PatchesThe problem has been patched in 15147cea8e42f6569a11603d661d71122f6a02dc. Users should upgrade to v0.36.0. WorkaroundsUntil a patch is available, users can:
Fixed in
0.36.0
References
Updated Mar 21, 2025 · Source: OSV.dev |
0.35.1
unknown
Dependencies (31)
+ 23 more |
|
0.35.0
unknown
1 CVE
CVE-2025-30160
GHSA-g8vq-v3mg-7mrg
Mar 21, 2025
Redlib allows a Denial of Service via DEFLATE Decompression Bomb in restore_preferences Form
High
Network
Low
None
None
A vulnerability has been identified in Redlib where an attacker can cause a denial-of-service (DOS) condition by submitting a specially crafted base2048-encoded DEFLATE decompression bomb to the restore_preferences form. This leads to excessive memory consumption and potential system instability, which can be exploited to disrupt Redlib instances. This vulnerability was introduced in 2e95e1fc6e2064ccfae87964b4860bda55eddb9a and fixed in 15147cea8e42f6569a11603d661d71122f6a02dc. ImpactWhat kind of vulnerability is it? Who is impacted? This vulnerability allows a remote attacker with network access to exploit the preference restoration mechanism by providing a compressed payload that expands dramatically upon decompression. The issue arises because the system automatically decompresses user-supplied data without enforcing size limits, potentially leading to:
PatchesThe problem has been patched in 15147cea8e42f6569a11603d661d71122f6a02dc. Users should upgrade to v0.36.0. WorkaroundsUntil a patch is available, users can:
Fixed in
0.36.0
References
Updated Mar 21, 2025 · Source: OSV.dev |
0.35.0
unknown
Dependencies (31)
+ 23 more |
|
0.34.0
unknown
1 CVE
CVE-2025-30160
GHSA-g8vq-v3mg-7mrg
Mar 21, 2025
Redlib allows a Denial of Service via DEFLATE Decompression Bomb in restore_preferences Form
High
Network
Low
None
None
A vulnerability has been identified in Redlib where an attacker can cause a denial-of-service (DOS) condition by submitting a specially crafted base2048-encoded DEFLATE decompression bomb to the restore_preferences form. This leads to excessive memory consumption and potential system instability, which can be exploited to disrupt Redlib instances. This vulnerability was introduced in 2e95e1fc6e2064ccfae87964b4860bda55eddb9a and fixed in 15147cea8e42f6569a11603d661d71122f6a02dc. ImpactWhat kind of vulnerability is it? Who is impacted? This vulnerability allows a remote attacker with network access to exploit the preference restoration mechanism by providing a compressed payload that expands dramatically upon decompression. The issue arises because the system automatically decompresses user-supplied data without enforcing size limits, potentially leading to:
PatchesThe problem has been patched in 15147cea8e42f6569a11603d661d71122f6a02dc. Users should upgrade to v0.36.0. WorkaroundsUntil a patch is available, users can:
Fixed in
0.36.0
References
Updated Mar 21, 2025 · Source: OSV.dev |
0.34.0
unknown
Dependencies (30)
+ 22 more |
|
0.33.2
unknown
1 CVE
CVE-2025-30160
GHSA-g8vq-v3mg-7mrg
Mar 21, 2025
Redlib allows a Denial of Service via DEFLATE Decompression Bomb in restore_preferences Form
High
Network
Low
None
None
A vulnerability has been identified in Redlib where an attacker can cause a denial-of-service (DOS) condition by submitting a specially crafted base2048-encoded DEFLATE decompression bomb to the restore_preferences form. This leads to excessive memory consumption and potential system instability, which can be exploited to disrupt Redlib instances. This vulnerability was introduced in 2e95e1fc6e2064ccfae87964b4860bda55eddb9a and fixed in 15147cea8e42f6569a11603d661d71122f6a02dc. ImpactWhat kind of vulnerability is it? Who is impacted? This vulnerability allows a remote attacker with network access to exploit the preference restoration mechanism by providing a compressed payload that expands dramatically upon decompression. The issue arises because the system automatically decompresses user-supplied data without enforcing size limits, potentially leading to:
PatchesThe problem has been patched in 15147cea8e42f6569a11603d661d71122f6a02dc. Users should upgrade to v0.36.0. WorkaroundsUntil a patch is available, users can:
Fixed in
0.36.0
References
Updated Mar 21, 2025 · Source: OSV.dev |
0.33.2
unknown
Dependencies (30)
+ 22 more |
|
0.33.1
unknown
1 CVE
CVE-2025-30160
GHSA-g8vq-v3mg-7mrg
Mar 21, 2025
Redlib allows a Denial of Service via DEFLATE Decompression Bomb in restore_preferences Form
High
Network
Low
None
None
A vulnerability has been identified in Redlib where an attacker can cause a denial-of-service (DOS) condition by submitting a specially crafted base2048-encoded DEFLATE decompression bomb to the restore_preferences form. This leads to excessive memory consumption and potential system instability, which can be exploited to disrupt Redlib instances. This vulnerability was introduced in 2e95e1fc6e2064ccfae87964b4860bda55eddb9a and fixed in 15147cea8e42f6569a11603d661d71122f6a02dc. ImpactWhat kind of vulnerability is it? Who is impacted? This vulnerability allows a remote attacker with network access to exploit the preference restoration mechanism by providing a compressed payload that expands dramatically upon decompression. The issue arises because the system automatically decompresses user-supplied data without enforcing size limits, potentially leading to:
PatchesThe problem has been patched in 15147cea8e42f6569a11603d661d71122f6a02dc. Users should upgrade to v0.36.0. WorkaroundsUntil a patch is available, users can:
Fixed in
0.36.0
References
Updated Mar 21, 2025 · Source: OSV.dev |
0.33.1
unknown
Dependencies (30)
+ 22 more |
|
0.31.0
unknown
1 CVE
CVE-2025-30160
GHSA-g8vq-v3mg-7mrg
Mar 21, 2025
Redlib allows a Denial of Service via DEFLATE Decompression Bomb in restore_preferences Form
High
Network
Low
None
None
A vulnerability has been identified in Redlib where an attacker can cause a denial-of-service (DOS) condition by submitting a specially crafted base2048-encoded DEFLATE decompression bomb to the restore_preferences form. This leads to excessive memory consumption and potential system instability, which can be exploited to disrupt Redlib instances. This vulnerability was introduced in 2e95e1fc6e2064ccfae87964b4860bda55eddb9a and fixed in 15147cea8e42f6569a11603d661d71122f6a02dc. ImpactWhat kind of vulnerability is it? Who is impacted? This vulnerability allows a remote attacker with network access to exploit the preference restoration mechanism by providing a compressed payload that expands dramatically upon decompression. The issue arises because the system automatically decompresses user-supplied data without enforcing size limits, potentially leading to:
PatchesThe problem has been patched in 15147cea8e42f6569a11603d661d71122f6a02dc. Users should upgrade to v0.36.0. WorkaroundsUntil a patch is available, users can:
Fixed in
0.36.0
References
Updated Mar 21, 2025 · Source: OSV.dev |
0.31.0
unknown
Dependencies (30)
+ 22 more |
|
0.30.2
unknown
1 CVE
CVE-2025-30160
GHSA-g8vq-v3mg-7mrg
Mar 21, 2025
Redlib allows a Denial of Service via DEFLATE Decompression Bomb in restore_preferences Form
High
Network
Low
None
None
A vulnerability has been identified in Redlib where an attacker can cause a denial-of-service (DOS) condition by submitting a specially crafted base2048-encoded DEFLATE decompression bomb to the restore_preferences form. This leads to excessive memory consumption and potential system instability, which can be exploited to disrupt Redlib instances. This vulnerability was introduced in 2e95e1fc6e2064ccfae87964b4860bda55eddb9a and fixed in 15147cea8e42f6569a11603d661d71122f6a02dc. ImpactWhat kind of vulnerability is it? Who is impacted? This vulnerability allows a remote attacker with network access to exploit the preference restoration mechanism by providing a compressed payload that expands dramatically upon decompression. The issue arises because the system automatically decompresses user-supplied data without enforcing size limits, potentially leading to:
PatchesThe problem has been patched in 15147cea8e42f6569a11603d661d71122f6a02dc. Users should upgrade to v0.36.0. WorkaroundsUntil a patch is available, users can:
Fixed in
0.36.0
References
Updated Mar 21, 2025 · Source: OSV.dev |
0.30.2
unknown
Dependencies (30)
+ 22 more |