Lucene search

K
osvGoogleOSV:GO-2022-0273
HistoryMay 18, 2022 - 6:23 p.m.

Panic due to crafted inputs in archive/zip

2022-05-1818:23:31
Google
osv.dev
26

7.7 High

AI Score

Confidence

High

0.003 Low

EPSS

Percentile

65.8%

The NewReader and OpenReader functions in archive/zip can cause a panic or an unrecoverable fatal error when reading an archive that claims to contain a large number of files, regardless of its actual size. This is caused by an incomplete fix for CVE-2021-33196.

CPENameOperatorVersion
stdliblt1.17.1
stdlibge1.17.0-0
stdliblt1.16.8