Логотип exploitDog
bind:"BDU:2025-14528" OR bind:"CVE-2025-58183"
Консоль
Логотип exploitDog

exploitDog

bind:"BDU:2025-14528" OR bind:"CVE-2025-58183"

Количество 12

Количество 12

fstec логотип

BDU:2025-14528

около 1 месяца назад

Уязвимость компонента tar.Reader языка программирования Go, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2025-58183

около 1 месяца назад

tar.Reader does not set a maximum size on the number of sparse region data blocks in GNU tar pax 1.0 sparse files. A maliciously-crafted archive containing a large number of sparse regions can cause a Reader to read an unbounded amount of data from the archive into memory. When reading from a compressed source, a small compressed input can result in large allocations.

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2025-58183

около 1 месяца назад

tar.Reader does not set a maximum size on the number of sparse region data blocks in GNU tar pax 1.0 sparse files. A maliciously-crafted archive containing a large number of sparse regions can cause a Reader to read an unbounded amount of data from the archive into memory. When reading from a compressed source, a small compressed input can result in large allocations.

CVSS3: 4.3
EPSS: Низкий
msrc логотип

CVE-2025-58183

около 1 месяца назад

Unbounded allocation when parsing GNU sparse map in archive/tar

EPSS: Низкий
debian логотип

CVE-2025-58183

около 1 месяца назад

tar.Reader does not set a maximum size on the number of sparse region ...

CVSS3: 4.3
EPSS: Низкий
rocky логотип

RLSA-2025:21816

4 дня назад

Moderate: delve and golang security update

EPSS: Низкий
github логотип

GHSA-9gcr-gp5f-jw27

около 1 месяца назад

tar.Reader does not set a maximum size on the number of sparse region data blocks in GNU tar pax 1.0 sparse files. A maliciously-crafted archive containing a large number of sparse regions can cause a Reader to read an unbounded amount of data from the archive into memory. When reading from a compressed source, a small compressed input can result in large allocations.

CVSS3: 3.3
EPSS: Низкий
oracle-oval логотип

ELSA-2025-21815

6 дней назад

ELSA-2025-21815: delve and golang security update (MODERATE)

EPSS: Низкий
oracle-oval логотип

ELSA-2025-22011

6 дней назад

ELSA-2025-22011: buildah security update (IMPORTANT)

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:3682-1

около 1 месяца назад

Security update for go1.24

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:03547-1

около 2 месяцев назад

Security update for go1.25

EPSS: Низкий
redos логотип

ROS-20251029-07

около 1 месяца назад

Множественные уязвимости golang

CVSS3: 8.2
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
fstec логотип
BDU:2025-14528

Уязвимость компонента tar.Reader языка программирования Go, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 4.3
0%
Низкий
около 1 месяца назад
ubuntu логотип
CVE-2025-58183

tar.Reader does not set a maximum size on the number of sparse region data blocks in GNU tar pax 1.0 sparse files. A maliciously-crafted archive containing a large number of sparse regions can cause a Reader to read an unbounded amount of data from the archive into memory. When reading from a compressed source, a small compressed input can result in large allocations.

CVSS3: 4.3
0%
Низкий
около 1 месяца назад
nvd логотип
CVE-2025-58183

tar.Reader does not set a maximum size on the number of sparse region data blocks in GNU tar pax 1.0 sparse files. A maliciously-crafted archive containing a large number of sparse regions can cause a Reader to read an unbounded amount of data from the archive into memory. When reading from a compressed source, a small compressed input can result in large allocations.

CVSS3: 4.3
0%
Низкий
около 1 месяца назад
msrc логотип
CVE-2025-58183

Unbounded allocation when parsing GNU sparse map in archive/tar

0%
Низкий
около 1 месяца назад
debian логотип
CVE-2025-58183

tar.Reader does not set a maximum size on the number of sparse region ...

CVSS3: 4.3
0%
Низкий
около 1 месяца назад
rocky логотип
RLSA-2025:21816

Moderate: delve and golang security update

0%
Низкий
4 дня назад
github логотип
GHSA-9gcr-gp5f-jw27

tar.Reader does not set a maximum size on the number of sparse region data blocks in GNU tar pax 1.0 sparse files. A maliciously-crafted archive containing a large number of sparse regions can cause a Reader to read an unbounded amount of data from the archive into memory. When reading from a compressed source, a small compressed input can result in large allocations.

CVSS3: 3.3
0%
Низкий
около 1 месяца назад
oracle-oval логотип
ELSA-2025-21815

ELSA-2025-21815: delve and golang security update (MODERATE)

6 дней назад
oracle-oval логотип
ELSA-2025-22011

ELSA-2025-22011: buildah security update (IMPORTANT)

6 дней назад
suse-cvrf логотип
SUSE-SU-2025:3682-1

Security update for go1.24

около 1 месяца назад
suse-cvrf логотип
SUSE-SU-2025:03547-1

Security update for go1.25

около 2 месяцев назад
redos логотип
ROS-20251029-07

Множественные уязвимости golang

CVSS3: 8.2
около 1 месяца назад

Уязвимостей на страницу