CVE-2021-41772 - log back

CVE-2021-41772 edited at 05 Nov 2021 10:33:35
Severity
- Unknown
+ Low
Remote
- Unknown
+ Remote
Type
- Unknown
+ Denial of service
Description
+ A security issue has been found in go before version 1.17.3. Reader.Open (the API implementing io/fs.FS introduced in Go 1.16) can be made to panic by an attacker providing either a crafted ZIP archive containing completely invalid names or an empty filename argument.
References
+ https://groups.google.com/g/golang-announce/c/0fM21h43arc
+ https://github.com/golang/go/issues/48085
+ https://github.com/golang/go/commit/b212ba68296b503b395e7d1838ca72a19030a6bf
CVE-2021-41772 created at 05 Nov 2021 10:30:54