CVE-2021-33196 log

Source
Severity Low
Remote Yes
Type Denial of service
Description
A security issue has been found in Go before version 1.16.5. Due to a pre-allocation optimization in zip.NewReader, a malformed archive which indicates it has a significant number of files can cause either a panic or memory exhaustion.
Group Package Affected Fixed Severity Status Ticket
AVG-2006 go 2:1.16.4-1 2:1.16.5-1 Medium Fixed
Date Advisory Group Package Severity Type
15 Jun 2021 ASA-202106-42 AVG-2006 go Medium multiple issues
References
https://groups.google.com/g/golang-announce/c/RgCMkAEQjSI/m/r_EP-NlKBgAJ
https://github.com/golang/go/issues/46242
https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=33912
https://github.com/golang/go/commit/895fb1bb6fc0d3c01c5ef7c8cbaf033d1fff9ad7