[GHSA-q6gq-997w-f55g] Infinite loop in xz#6316
Conversation
|
Actually, reading further and I think this advisory shouldn't actually mention "github.com/ulikunitz/xz". The infinite loop vuln mentioned here is already covered by this GHSA: GHSA-25xm-hr59-7c27. It looks like this GHSA is actually about the infinite read loop in |
|
Hi @Fidget-Grep, |
2b29c03
into
Fidget-Grep/advisory-improvement-6316
|
Hi @Fidget-Grep! Thank you so much for contributing to the GitHub Advisory Database. This database is free, open, and accessible to all, and it's people like you who make it great. Thanks for choosing to help others. We hope you send in more contributions in the future! |
Updates
Comments
As per the Go Vulnerability Database (https://pkg.go.dev/vuln/GO-2021-0142) this vulnerability also affects the Go Standard Library
encoding/binary. I've added this library as an affected package and listed the appropriate affected versions as per the advisory. I also added some helpful reference links and a missing source code link to the "xz" project.Let me know if any information is missing or incorrect, thanks.