CVE-2021-27919
Summary
| CVE | CVE-2021-27919 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-03-11 00:15:00 UTC |
| Updated | 2023-11-07 03:32:00 UTC |
| Description | archive/zip in Go 1.16.x before 1.16.1 allows attackers to cause a denial of service (panic) upon attempted use of the Reader.Open API for a ZIP archive in which ../ occurs at the beginning of any filename. |
Risk And Classification
Problem Types: NVD-CWE-noinfo
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Fedoraproject | Fedora | 34 | All | All | All |
| Operating System | Fedoraproject | Fedora | 35 | All | All | All |
| Application | Golang | Go | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Go: Multiple Vulnerabilities (GLSA 202208-02) — Gentoo security | GENTOO | security.gentoo.org | |
| [SECURITY] Fedora 34 Update: golang-1.16.8-1.fc34 - package-announce - Fedora Mailing-Lists | lists.fedoraproject.org | ||
| [security] Go 1.16.1 and Go 1.15.9 are released | MISC | groups.google.com | Mailing List, Vendor Advisory |
| [SECURITY] Fedora 35 Update: golang-1.16.8-2.fc35 - package-announce - Fedora Mailing-Lists | FEDORA | lists.fedoraproject.org | |
| [SECURITY] Fedora 34 Update: golang-1.16.8-1.fc34 - package-announce - Fedora Mailing-Lists | FEDORA | lists.fedoraproject.org | |
| [SECURITY] Fedora 35 Update: golang-1.16.8-2.fc35 - package-announce - Fedora Mailing-Lists | lists.fedoraproject.org | ||
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 174835 SUSE Enterprise Linux Security update for go1.16 (SUSE-SU-2021:0937-1)
- 174854 SUSE Enterprise Linux Security update for go1.16 (SUSE-SU-2021:0937-1)
- 281921 Fedora Security Update for golang (FEDORA-2021-6a3024b3fd)
- 354041 Amazon Linux Security Advisory for golang : ALAS2-2022-1830
- 378883 Splunk Enterprise August Third Party Package Updates (SVD-2023-0808)
- 501568 Alpine Linux Security Update for go
- 501857 Alpine Linux Security Update for go
- 690234 Free Berkeley Software Distribution (FreeBSD) Security Update for go (72709326-81f7-11eb-950a-00155d646401)
- 710584 Gentoo Linux Go Multiple Vulnerabilities (GLSA 202208-02)