CVE-2021-39293

Description

In archive/zip in Go before 1.16.8 and 1.17.x before 1.17.1, a crafted archive header (falsely designating that many files are present) can cause a NewReader or OpenReader panic. NOTE: this issue exists because of an incomplete fix for CVE-2021-33196.

Risk Information

Base Score
7.5
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS Score
Exploitation Probability
0.039

Associated Vulnerability

VulnerabilityOS Platform
(RHSA-2022:1819) go-toolset:rhel8 security and bug fix update delve-1.7.2-1.module+el8.6.0+12972+ebab5911.x86_64.rpmLinux
(RHSA-2022:1819) go-toolset:rhel8 security and bug fix update delve-debugsource-1.7.2-1.module+el8.6.0+12972+ebab5911.x86_64.rpmLinux
(RHSA-2022:1819) go-toolset:rhel8 security and bug fix update go-toolset-1.17.7-1.module+el8.6.0+14297+32a15e19.x86_64.rpmLinux
(RHSA-2022:1819) go-toolset:rhel8 security and bug fix update golang-1.17.7-1.module+el8.6.0+14297+32a15e19.x86_64.rpmLinux
(RHSA-2022:1819) go-toolset:rhel8 security and bug fix update golang-bin-1.17.7-1.module+el8.6.0+14297+32a15e19.x86_64.rpmLinux
(RHSA-2022:1819) go-toolset:rhel8 security and bug fix update golang-docs-1.17.7-1.module+el8.6.0+14297+32a15e19.noarch.rpmLinux
(RHSA-2022:1819) go-toolset:rhel8 security and bug fix update golang-misc-1.17.7-1.module+el8.6.0+14297+32a15e19.noarch.rpmLinux
(RHSA-2022:1819) go-toolset:rhel8 security and bug fix update golang-race-1.17.7-1.module+el8.6.0+14297+32a15e19.x86_64.rpmLinux
(RHSA-2022:1819) go-toolset:rhel8 security and bug fix update golang-src-1.17.7-1.module+el8.6.0+14297+32a15e19.noarch.rpmLinux
(RHSA-2022:1819) go-toolset:rhel8 security and bug fix update golang-tests-1.17.7-1.module+el8.6.0+14297+32a15e19.noarch.rpmLinux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234