UBUNTU-CVE-2022-2879
Dashboard / Vulnerabilities / UBUNTU-CVE-2022-2879
UBUNTU-CVE-2022-2879
Summary:
Details: Reader.Read does not set a limit on the maximum size of file headers. A maliciously crafted archive could cause Read to allocate unbounded amounts of memory, potentially causing resource exhaustion or panics. After fix, Reader.Read limits the maximum size of header blocks to 1 MiB.
References: https://ubuntu.com/security/CVE-2022-2879, https://go.dev/issue/54853, https://github.com/golang/go/commit/4fa773cdefd20be093c84f731be7d4febf5536fa, https://github.com/golang/go/commit/0a723816cd205576945fa57fbdde7e6532d59d08, https://ubuntu.com/security/notices/USN-6038-1, https://ubuntu.com/security/notices/USN-6038-2, https://www.cve.org/CVERecord?id=CVE-2022-2879
Affected packages
Package
Name: golang-1.10
Purl: pkg:deb/ubuntu/golang-1.10?arch=source&distro=trusty
Affected ranges
Type: ECOSYSTEM
Events:
