Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:29662
HistoryMar 11, 2021 - 3:11 a.m.

Denial Of Service (DoS)

2021-03-1103:11:01
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
7

0.001 Low

EPSS

Percentile

29.9%

archive/zip in github.com/golang/go is vulnerable to denial of service (DoS). The use of Reader.Open API on a Zip file that contains a file prefixed with โ€œโ€ฆ/โ€, such as Open(...) causes a panic in the function toValidName when attempting to strip the prefixed path components.