CVE-2021-33196

Severity CVSS v4.0:
Pending analysis
Type:
CWE-20 Input Validation
Publication date:
02/08/2021
Last modified:
20/04/2023

Description

In archive/zip in Go before 1.15.13 and 1.16.x before 1.16.5, a crafted file count (in an archive's header) can cause a NewReader or OpenReader panic.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:golang:go:*:*:*:*:*:*:*:* 1.15.13 (excluding)
cpe:2.3:a:golang:go:*:*:*:*:*:*:*:* 1.16.0 (including) 1.16.5 (excluding)
cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*