GHSA-967g-cjx4-h7j6
Dashboard / Vulnerabilities / GHSA-967g-cjx4-h7j6
GHSA-967g-cjx4-h7j6
Summary: Duplicate Advisory: go-codec-dagpb vulnerable to panic when decoding invalid blocks
Details: ## Duplicate Advisory This advisory has been withdrawn because it is a duplicate of GHSA-g3vv-g2j5-45f2. This link is maintained to preserve external references. ## Original Description go-codec-dagpb is an implementation of the DAG-PB spec for Go. The dag-pb codec can panic when decoding invalid blocks. This issue has been patched in version 1.3.1.
References: https://nvd.nist.gov/vuln/detail/CVE-2022-2584, https://github.com/ipld/go-codec-dagpb/commit/a17ace35cc760a2698645c09868f9050fa219f57, https://pkg.go.dev/vuln/GO-2022-0422, github.com/ipld/go-codec-dagpb
Affected packages
Package
Name: github.com/ipld/go-codec-dagpb
Purl: pkg:golang/github.com/ipld/go-codec-dagpb
Affected ranges
Type: SEMVER
Events:
