Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 19

Количество 19

github логотип

GHSA-jc7w-c686-c4v9

11 месяцев назад

github.com/ulikunitz/xz leaks memory when decoding a corrupted multiple LZMA archives

CVSS3: 5.3
EPSS: Низкий
ubuntu логотип

CVE-2025-58058

11 месяцев назад

xz is a pure golang package for reading and writing xz-compressed files. Prior to version 0.5.14, it is possible to put data in front of an LZMA-encoded byte stream without detecting the situation while reading the header. This can lead to increased memory consumption because the current implementation allocates the full decoding buffer directly after reading the header. The LZMA header doesn't include a magic number or has a checksum to detect such an issue according to the specification. Note that the code recognizes the issue later while reading the stream, but at this time the memory allocation has already been done. This issue has been patched in version 0.5.14.

CVSS3: 5.3
EPSS: Низкий
redhat логотип

CVE-2025-58058

11 месяцев назад

xz is a pure golang package for reading and writing xz-compressed files. Prior to version 0.5.14, it is possible to put data in front of an LZMA-encoded byte stream without detecting the situation while reading the header. This can lead to increased memory consumption because the current implementation allocates the full decoding buffer directly after reading the header. The LZMA header doesn't include a magic number or has a checksum to detect such an issue according to the specification. Note that the code recognizes the issue later while reading the stream, but at this time the memory allocation has already been done. This issue has been patched in version 0.5.14.

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2025-58058

11 месяцев назад

xz is a pure golang package for reading and writing xz-compressed files. Prior to version 0.5.14, it is possible to put data in front of an LZMA-encoded byte stream without detecting the situation while reading the header. This can lead to increased memory consumption because the current implementation allocates the full decoding buffer directly after reading the header. The LZMA header doesn't include a magic number or has a checksum to detect such an issue according to the specification. Note that the code recognizes the issue later while reading the stream, but at this time the memory allocation has already been done. This issue has been patched in version 0.5.14.

CVSS3: 5.3
EPSS: Низкий
msrc логотип

CVE-2025-58058

11 месяцев назад

github.com/ulikunitz/xz leaks memory when decoding a corrupted multiple LZMA archives

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2025-58058

11 месяцев назад

xz is a pure golang package for reading and writing xz-compressed file ...

CVSS3: 5.3
EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2025:20031-1

9 месяцев назад

Security update for warewulf4

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:03448-1

10 месяцев назад

Security update for warewulf4

EPSS: Низкий
fstec логотип

BDU:2025-12797

11 месяцев назад

Уязвимость языка программирования Go, связанная с неограниченным распределением ресурсов, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 5.3
EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:20192-1

6 месяцев назад

Security update for tailscale

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2025:20073-1

9 месяцев назад

Security update for alloy

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:0383-1

6 месяцев назад

Security update for rekor

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:4121-1

9 месяцев назад

Security update for alloy

EPSS: Низкий
redos логотип

ROS-20251124-04

8 месяцев назад

Уязвимость golang-github-ulikunitz-xz

CVSS3: 5.3
EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:20105-1

6 месяцев назад

Security update for sbctl

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:21151-1

около 1 месяца назад

Security update for warewulf4

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2025:20160-1

8 месяцев назад

Security update for hauler

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2025:20117-1

8 месяцев назад

Security update for trivy

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:20798-1

6 месяцев назад

Security update for trivy

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-jc7w-c686-c4v9

github.com/ulikunitz/xz leaks memory when decoding a corrupted multiple LZMA archives

CVSS3: 5.3
0%
Низкий
11 месяцев назад
ubuntu логотип
CVE-2025-58058

xz is a pure golang package for reading and writing xz-compressed files. Prior to version 0.5.14, it is possible to put data in front of an LZMA-encoded byte stream without detecting the situation while reading the header. This can lead to increased memory consumption because the current implementation allocates the full decoding buffer directly after reading the header. The LZMA header doesn't include a magic number or has a checksum to detect such an issue according to the specification. Note that the code recognizes the issue later while reading the stream, but at this time the memory allocation has already been done. This issue has been patched in version 0.5.14.

CVSS3: 5.3
0%
Низкий
11 месяцев назад
redhat логотип
CVE-2025-58058

xz is a pure golang package for reading and writing xz-compressed files. Prior to version 0.5.14, it is possible to put data in front of an LZMA-encoded byte stream without detecting the situation while reading the header. This can lead to increased memory consumption because the current implementation allocates the full decoding buffer directly after reading the header. The LZMA header doesn't include a magic number or has a checksum to detect such an issue according to the specification. Note that the code recognizes the issue later while reading the stream, but at this time the memory allocation has already been done. This issue has been patched in version 0.5.14.

CVSS3: 5.3
0%
Низкий
11 месяцев назад
nvd логотип
CVE-2025-58058

xz is a pure golang package for reading and writing xz-compressed files. Prior to version 0.5.14, it is possible to put data in front of an LZMA-encoded byte stream without detecting the situation while reading the header. This can lead to increased memory consumption because the current implementation allocates the full decoding buffer directly after reading the header. The LZMA header doesn't include a magic number or has a checksum to detect such an issue according to the specification. Note that the code recognizes the issue later while reading the stream, but at this time the memory allocation has already been done. This issue has been patched in version 0.5.14.

CVSS3: 5.3
0%
Низкий
11 месяцев назад
msrc логотип
CVE-2025-58058

github.com/ulikunitz/xz leaks memory when decoding a corrupted multiple LZMA archives

CVSS3: 5.3
0%
Низкий
11 месяцев назад
debian логотип
CVE-2025-58058

xz is a pure golang package for reading and writing xz-compressed file ...

CVSS3: 5.3
0%
Низкий
11 месяцев назад
suse-cvrf логотип
openSUSE-SU-2025:20031-1

Security update for warewulf4

0%
Низкий
9 месяцев назад
suse-cvrf логотип
SUSE-SU-2025:03448-1

Security update for warewulf4

0%
Низкий
10 месяцев назад
fstec логотип
BDU:2025-12797

Уязвимость языка программирования Go, связанная с неограниченным распределением ресурсов, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 5.3
0%
Низкий
11 месяцев назад
suse-cvrf логотип
openSUSE-SU-2026:20192-1

Security update for tailscale

6 месяцев назад
suse-cvrf логотип
openSUSE-SU-2025:20073-1

Security update for alloy

9 месяцев назад
suse-cvrf логотип
SUSE-SU-2026:0383-1

Security update for rekor

6 месяцев назад
suse-cvrf логотип
SUSE-SU-2025:4121-1

Security update for alloy

9 месяцев назад
redos логотип
ROS-20251124-04

Уязвимость golang-github-ulikunitz-xz

CVSS3: 5.3
0%
Низкий
8 месяцев назад
suse-cvrf логотип
openSUSE-SU-2026:20105-1

Security update for sbctl

6 месяцев назад
suse-cvrf логотип
openSUSE-SU-2026:21151-1

Security update for warewulf4

около 1 месяца назад
suse-cvrf логотип
openSUSE-SU-2025:20160-1

Security update for hauler

8 месяцев назад
suse-cvrf логотип
openSUSE-SU-2025:20117-1

Security update for trivy

8 месяцев назад
suse-cvrf логотип
openSUSE-SU-2026:20798-1

Security update for trivy

6 месяцев назад

Уязвимостей на страницу