[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

250108

 
 

909

 
 

196064

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

ALAS2-2021-1694 --- golang

ID: oval:org.secpod.oval:def:1700697Date: (C)2021-08-10   (M)2023-11-30
Class: PATCHFamily: unix




A vulnerability was found in archive/zip of the Go standard library. Applications written in Go can panic or potentially exhaust system memory when parsing malformed ZIP files. A flaw was found in golang. A panic can be triggered by an attacker in a privileged network position without access to the server certificate"s private key, as long as a trusted ECDSA or Ed25519 certificate for the server exists , or the client is configured with Config.InsecureSkipVerify. Clients that disable all TLS_RSA cipher suites , as well as TLS 1.3-only clients, are unaffected

Platform:
Amazon Linux 2
Product:
golang
Reference:
ALAS2-2021-1694
CVE-2021-33196
CVE-2021-34558
CVE    2
CVE-2021-34558
CVE-2021-33196
CPE    2
cpe:/o:amazon:linux:2
cpe:/a:golang:golang

© SecPod Technologies