CVE-2021-39293

Name
CVE-2021-39293
Description
In archive/zip in Go before 1.16.8 and 1.17.x before 1.17.1, a crafted archive header (falsely designating that many files are present) can cause a NewReader or OpenReader panic. NOTE: this issue exists because of an incomplete fix for CVE-2021-33196.
NVD Severity
medium
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
CONFIRM https://groups.google.com/g/golang-announce/c/dx9d7IOseHw
Third Party Advisory https://security.netapp.com/advisory/ntap-20220217-0009/

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:golang:go:*:*:*:*:*:*:*:* go >= None < 1.16.8
cpe:2.3:a:golang:go:*:*:*:*:*:*:*:* go >= 1.17.0 < 1.17.1

Vulnerable and fixed packages

Source package Branch Version Maintainer Status