CVE-2021-39293
Summary
| CVE | CVE-2021-39293 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-01-24 01:15:00 UTC |
| Updated | 2023-04-20 00:15:00 UTC |
| Description | In archive/zip in Go before 1.16.8 and 1.17.x before 1.17.1, a crafted archive header (falsely designating that many files are present) can cause a NewReader or OpenReader panic. NOTE: this issue exists because of an incomplete fix for CVE-2021-33196. |
NVD Known Affected Configurations (CPE 2.3)
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 159810 Oracle Enterprise Linux Security Update for go-toolset:ol8 (ELSA-2022-1819)
- 179017 Debian Security Update for golang-1.8 (DLA 2891-1)
- 179018 Debian Security Update for golang-1.7 (DLA 2892-1)
- 179618 Debian Security Update for golang-1.15 (CVE-2021-39293)
- 181743 Debian Security Update for golang-1.11 (DLA 3395-1)
- 240276 Red Hat Update for go-toolset:rhel8 (RHSA-2022:1819)
- 353977 Amazon Linux Security Advisory for golang : ALAS2-2022-1811
- 354041 Amazon Linux Security Advisory for golang : ALAS2-2022-1830
- 378883 Splunk Enterprise August Third Party Package Updates (SVD-2023-0808)
- 501862 Alpine Linux Security Update for go
- 502090 Alpine Linux Security Update for go
- 590976 Siemens SCALANCE LPE9403 Third-Party Multiple Vulnerabilities (ICSA-22-167-09) (SSA-222547)
- 671452 EulerOS Security Update for golang (EulerOS-SA-2022-1449)
- 671472 EulerOS Security Update for golang (EulerOS-SA-2022-1428)
- 671610 EulerOS Security Update for golang (EulerOS-SA-2022-1534)
- 671616 EulerOS Security Update for golang (EulerOS-SA-2022-1566)
- 671621 EulerOS Security Update for golang (EulerOS-SA-2022-1660)
- 671645 EulerOS Security Update for golang (EulerOS-SA-2022-1646)
- 690040 Free Berkeley Software Distribution (FreeBSD) Security Update for go (4ea1082a-1259-11ec-b4fa-dd5a552bdd17)
- 751202 OpenSUSE Security Update for go1.16 (openSUSE-SU-2021:3292-1)
- 751228 OpenSUSE Security Update for go1.16 (openSUSE-SU-2021:1342-1)
- 940527 AlmaLinux Security Update for go-toolset:rhel8 (ALSA-2022:1819)
- 960394 Rocky Linux Security Update for go-toolset:rhel8 (RLSA-2022:1819)