|
6 | 6 | "aliases": [ |
7 | 7 | "CVE-2020-16845" |
8 | 8 | ], |
9 | | - "summary": "Infinite loop in xz", |
| 9 | + "summary": "Infinite loop in Go standard library encoding/binary", |
10 | 10 | "details": "Go before 1.13.15 and 14.x before 1.14.7 can have an infinite read loop in ReadUvarint and ReadVarint in encoding/binary via invalid inputs.", |
11 | 11 | "severity": [ |
12 | 12 | { |
|
15 | 15 | } |
16 | 16 | ], |
17 | 17 | "affected": [ |
18 | | - { |
19 | | - "package": { |
20 | | - "ecosystem": "Go", |
21 | | - "name": "github.com/ulikunitz/xz" |
22 | | - }, |
23 | | - "ranges": [ |
24 | | - { |
25 | | - "type": "ECOSYSTEM", |
26 | | - "events": [ |
27 | | - { |
28 | | - "introduced": "0" |
29 | | - }, |
30 | | - { |
31 | | - "fixed": "0.5.8" |
32 | | - } |
33 | | - ] |
34 | | - } |
35 | | - ] |
36 | | - }, |
37 | 18 | { |
38 | 19 | "package": { |
39 | 20 | "ecosystem": "Go", |
|
79 | 60 | "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-16845" |
80 | 61 | }, |
81 | 62 | { |
82 | | - "type": "WEB", |
83 | | - "url": "https://github.com/ulikunitz/xz/issues/35" |
84 | | - }, |
85 | | - { |
86 | | - "type": "WEB", |
87 | | - "url": "https://github.com/ulikunitz/xz/commit/69c6093c7b2397b923acf82cb378f55ab2652b9b" |
| 63 | + "type": "PACKAGE", |
| 64 | + "url": "https://github.com/golang/go" |
88 | 65 | }, |
89 | 66 | { |
90 | 67 | "type": "WEB", |
91 | | - "url": "https://www.oracle.com/security-alerts/cpuApr2021.html" |
| 68 | + "url": "https://go.dev/issue/40618" |
92 | 69 | }, |
93 | 70 | { |
94 | 71 | "type": "WEB", |
95 | | - "url": "https://www.debian.org/security/2021/dsa-4848" |
| 72 | + "url": "https://groups.google.com/forum/#!topic/golang-announce/NyPIaucMgXo" |
96 | 73 | }, |
97 | 74 | { |
98 | 75 | "type": "WEB", |
99 | | - "url": "https://security.netapp.com/advisory/ntap-20200924-0002" |
| 76 | + "url": "https://groups.google.com/forum/#!topic/golang-announce/_ulYYcIWg3Q" |
100 | 77 | }, |
101 | 78 | { |
102 | 79 | "type": "WEB", |
103 | | - "url": "https://pkg.go.dev/vuln/GO-2021-0142" |
| 80 | + "url": "https://lists.debian.org/debian-lts-announce/2020/11/msg00037.html" |
104 | 81 | }, |
105 | 82 | { |
106 | 83 | "type": "WEB", |
107 | | - "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/WV2VWKFTH4EJGZBZALVUJQJOAQB5MDQ4" |
| 84 | + "url": "https://lists.debian.org/debian-lts-announce/2020/11/msg00038.html" |
108 | 85 | }, |
109 | 86 | { |
110 | 87 | "type": "WEB", |
111 | | - "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/TACQFZDPA7AUR6TRZBCX2RGRFSDYLI7O" |
| 88 | + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/6RCFJTMKHY5ICGEM5BUFUEDDGSPJ25XU" |
112 | 89 | }, |
113 | 90 | { |
114 | 91 | "type": "WEB", |
115 | 92 | "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/KWRBAH4UZJO3RROQ72SYCUPFCJFA22FO" |
116 | 93 | }, |
117 | 94 | { |
118 | 95 | "type": "WEB", |
119 | | - "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/6RCFJTMKHY5ICGEM5BUFUEDDGSPJ25XU" |
120 | | - }, |
121 | | - { |
122 | | - "type": "WEB", |
123 | | - "url": "https://lists.debian.org/debian-lts-announce/2020/11/msg00038.html" |
| 96 | + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/TACQFZDPA7AUR6TRZBCX2RGRFSDYLI7O" |
124 | 97 | }, |
125 | 98 | { |
126 | 99 | "type": "WEB", |
127 | | - "url": "https://lists.debian.org/debian-lts-announce/2020/11/msg00037.html" |
| 100 | + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/WV2VWKFTH4EJGZBZALVUJQJOAQB5MDQ4" |
128 | 101 | }, |
129 | 102 | { |
130 | 103 | "type": "WEB", |
131 | | - "url": "https://groups.google.com/g/golang-announce/c/NyPIaucMgXo" |
| 104 | + "url": "https://pkg.go.dev/vuln/GO-2021-0142" |
132 | 105 | }, |
133 | 106 | { |
134 | 107 | "type": "WEB", |
135 | | - "url": "https://groups.google.com/forum/#!topic/golang-announce/_ulYYcIWg3Q" |
| 108 | + "url": "https://security.netapp.com/advisory/ntap-20200924-0002" |
136 | 109 | }, |
137 | 110 | { |
138 | 111 | "type": "WEB", |
139 | | - "url": "https://groups.google.com/forum/#!topic/golang-announce/NyPIaucMgXo" |
| 112 | + "url": "https://www.debian.org/security/2021/dsa-4848" |
140 | 113 | }, |
141 | 114 | { |
142 | 115 | "type": "WEB", |
143 | | - "url": "https://go.dev/issue/40618" |
144 | | - }, |
145 | | - { |
146 | | - "type": "PACKAGE", |
147 | | - "url": "https://github.com/ulikunitz/xz" |
| 116 | + "url": "https://www.oracle.com/security-alerts/cpuApr2021.html" |
148 | 117 | }, |
149 | 118 | { |
150 | 119 | "type": "WEB", |
|
0 commit comments