Описание
tar.Reader can allocate an unbounded amount of memory when reading a maliciously-crafted archive containing a large number of sparse regions encoded in the "old GNU sparse map" format.
Ссылки
- Patch
- Issue Tracking
- Mailing ListRelease Notes
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 1.25.9 (исключая)Версия от 1.26.0 (включая) до 1.26.2 (исключая)
Одно из
cpe:2.3:a:golang:go:*:*:*:*:*:*:*:*
cpe:2.3:a:golang:go:*:*:*:*:*:*:*:*
EPSS
Процентиль: 21%
0.0029
Низкий
5.5 Medium
CVSS3
Дефекты
CWE-770
Связанные уязвимости
CVSS3: 5.5
ubuntu
5 месяцев назад
tar.Reader can allocate an unbounded amount of memory when reading a maliciously-crafted archive containing a large number of sparse regions encoded in the "old GNU sparse map" format.
CVSS3: 4.3
redhat
5 месяцев назад
tar.Reader can allocate an unbounded amount of memory when reading a maliciously-crafted archive containing a large number of sparse regions encoded in the "old GNU sparse map" format.
CVSS3: 5.5
debian
5 месяцев назад
tar.Reader can allocate an unbounded amount of memory when reading a m ...
EPSS
Процентиль: 21%
0.0029
Низкий
5.5 Medium
CVSS3
Дефекты
CWE-770