Skip to content

Commit 589f2f9

Browse files
committed
1 parent 0f4b449 commit 589f2f9

File tree

1 file changed

+15
-46
lines changed

1 file changed

+15
-46
lines changed

advisories/github-reviewed/2021/12/GHSA-q6gq-997w-f55g/GHSA-q6gq-997w-f55g.json

Lines changed: 15 additions & 46 deletions
Original file line numberDiff line numberDiff line change
@@ -6,7 +6,7 @@
66
"aliases": [
77
"CVE-2020-16845"
88
],
9-
"summary": "Infinite loop in xz",
9+
"summary": "Infinite loop in Go standard library encoding/binary",
1010
"details": "Go before 1.13.15 and 14.x before 1.14.7 can have an infinite read loop in ReadUvarint and ReadVarint in encoding/binary via invalid inputs.",
1111
"severity": [
1212
{
@@ -15,25 +15,6 @@
1515
}
1616
],
1717
"affected": [
18-
{
19-
"package": {
20-
"ecosystem": "Go",
21-
"name": "github.com/ulikunitz/xz"
22-
},
23-
"ranges": [
24-
{
25-
"type": "ECOSYSTEM",
26-
"events": [
27-
{
28-
"introduced": "0"
29-
},
30-
{
31-
"fixed": "0.5.8"
32-
}
33-
]
34-
}
35-
]
36-
},
3718
{
3819
"package": {
3920
"ecosystem": "Go",
@@ -79,72 +60,60 @@
7960
"url": "https://nvd.nist.gov/vuln/detail/CVE-2020-16845"
8061
},
8162
{
82-
"type": "WEB",
83-
"url": "https://github.com/ulikunitz/xz/issues/35"
84-
},
85-
{
86-
"type": "WEB",
87-
"url": "https://github.com/ulikunitz/xz/commit/69c6093c7b2397b923acf82cb378f55ab2652b9b"
63+
"type": "PACKAGE",
64+
"url": "https://github.com/golang/go"
8865
},
8966
{
9067
"type": "WEB",
91-
"url": "https://www.oracle.com/security-alerts/cpuApr2021.html"
68+
"url": "https://go.dev/issue/40618"
9269
},
9370
{
9471
"type": "WEB",
95-
"url": "https://www.debian.org/security/2021/dsa-4848"
72+
"url": "https://groups.google.com/forum/#!topic/golang-announce/NyPIaucMgXo"
9673
},
9774
{
9875
"type": "WEB",
99-
"url": "https://security.netapp.com/advisory/ntap-20200924-0002"
76+
"url": "https://groups.google.com/forum/#!topic/golang-announce/_ulYYcIWg3Q"
10077
},
10178
{
10279
"type": "WEB",
103-
"url": "https://pkg.go.dev/vuln/GO-2021-0142"
80+
"url": "https://lists.debian.org/debian-lts-announce/2020/11/msg00037.html"
10481
},
10582
{
10683
"type": "WEB",
107-
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/WV2VWKFTH4EJGZBZALVUJQJOAQB5MDQ4"
84+
"url": "https://lists.debian.org/debian-lts-announce/2020/11/msg00038.html"
10885
},
10986
{
11087
"type": "WEB",
111-
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/TACQFZDPA7AUR6TRZBCX2RGRFSDYLI7O"
88+
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/6RCFJTMKHY5ICGEM5BUFUEDDGSPJ25XU"
11289
},
11390
{
11491
"type": "WEB",
11592
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/KWRBAH4UZJO3RROQ72SYCUPFCJFA22FO"
11693
},
11794
{
11895
"type": "WEB",
119-
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/6RCFJTMKHY5ICGEM5BUFUEDDGSPJ25XU"
120-
},
121-
{
122-
"type": "WEB",
123-
"url": "https://lists.debian.org/debian-lts-announce/2020/11/msg00038.html"
96+
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/TACQFZDPA7AUR6TRZBCX2RGRFSDYLI7O"
12497
},
12598
{
12699
"type": "WEB",
127-
"url": "https://lists.debian.org/debian-lts-announce/2020/11/msg00037.html"
100+
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/WV2VWKFTH4EJGZBZALVUJQJOAQB5MDQ4"
128101
},
129102
{
130103
"type": "WEB",
131-
"url": "https://groups.google.com/g/golang-announce/c/NyPIaucMgXo"
104+
"url": "https://pkg.go.dev/vuln/GO-2021-0142"
132105
},
133106
{
134107
"type": "WEB",
135-
"url": "https://groups.google.com/forum/#!topic/golang-announce/_ulYYcIWg3Q"
108+
"url": "https://security.netapp.com/advisory/ntap-20200924-0002"
136109
},
137110
{
138111
"type": "WEB",
139-
"url": "https://groups.google.com/forum/#!topic/golang-announce/NyPIaucMgXo"
112+
"url": "https://www.debian.org/security/2021/dsa-4848"
140113
},
141114
{
142115
"type": "WEB",
143-
"url": "https://go.dev/issue/40618"
144-
},
145-
{
146-
"type": "PACKAGE",
147-
"url": "https://github.com/ulikunitz/xz"
116+
"url": "https://www.oracle.com/security-alerts/cpuApr2021.html"
148117
},
149118
{
150119
"type": "WEB",

0 commit comments

Comments
 (0)