CVE-2021-41772 log
| Source |
|
| Severity | Low |
| Remote | Yes |
| Type | Denial of service |
| Description | A security issue has been found in go before version 1.17.3. Reader.Open (the API implementing io/fs.FS introduced in Go 1.16) can be made to panic by an attacker providing either a crafted ZIP archive containing completely invalid names or an empty filename argument. |
| Group | Package | Affected | Fixed | Severity | Status | Ticket |
|---|---|---|---|---|---|---|
| AVG-2527 | go | 2:1.17.2-2 | 2:1.17.3-1 | Low | Fixed |
| References |
|---|
https://groups.google.com/g/golang-announce/c/0fM21h43arc https://github.com/golang/go/issues/48085 https://github.com/golang/go/commit/b212ba68296b503b395e7d1838ca72a19030a6bf |