CVE-2022-2879

CVE-2022-2879

Reader.Read does not set a limit on the maximum size of file headers. A maliciously crafted archive could cause Read to allocate unbounded amounts of memory, potentially causing resource exhaustion or panics. After fix, Reader.Read limits the maximum size of header blocks to 1 MiB.

Source: CVE-2022-2879

답글 남기기

이메일 주소는 공개되지 않습니다. 필수 필드는 *로 표시됩니다