Lucene search

K
osvGoogleOSV:GHSA-Q6GQ-997W-F55G
HistoryDec 16, 2021 - 7:16 p.m.

Infinite loop in xz

2021-12-1619:16:40
Google
osv.dev
13

0.037 Low

EPSS

Percentile

91.9%

Go before 1.13.15 and 14.x before 1.14.7 can have an infinite read loop in ReadUvarint and ReadVarint in encoding/binary via invalid inputs.

CPENameOperatorVersion
github.com/ulikunitz/xzlt0.5.8

References