CVE-2024-24789

Name
CVE-2024-24789
Description
The archive/zip package's handling of certain types of invalid zip files differs from the behavior of most zip implementations. This misalignment could be exploited to create an zip file with contents that vary depending on the implementation reading the file. The archive/zip package now rejects files containing these errors.
NVD Severity
unknown
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
Mailing List http://www.openwall.com/lists/oss-security/2024/06/04/1
Patch https://go.dev/cl/585397
Issue Tracking https://go.dev/issue/66869
Release Notes https://groups.google.com/g/golang-announce/c/XbxouI9gY7k/m/TuoGEhxIEwAJ
security@golang.org https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/U5YAEIA6IUHUNGJ7AIXXPQT6D2GYENX7/
Third Party Advisory https://pkg.go.dev/vuln/GO-2024-2888
af854a3a-2127-422b-91ae-364da2661108 https://security.netapp.com/advisory/ntap-20250131-0008/

Match rules

CPE URI Source package Min version Max version
archive/zip >= 0 < 1.21.11
archive/zip >= 1.22.0-0 < 1.22.4

Vulnerable and fixed packages

Source package Branch Version Maintainer Status