Bug#989492: golang-1.16: CVE-2021-33196: archive/zip: malformed archive may cause panic or memory exhaustion

2021-06-05 Thread Salvatore Bonaccorso
Hi, On Sat, Jun 05, 2021 at 07:17:44PM +0800, Shengjing Zhu wrote: > Hi Salvatore, > > On Sat, Jun 5, 2021 at 4:12 PM Salvatore Bonaccorso wrote: > > Hi, > > > > The following vulnerability was published for golang-1.16. > > > > CVE-2021-33196[0]: > > How does security-tracker pull the cve

Bug#989492: golang-1.16: CVE-2021-33196: archive/zip: malformed archive may cause panic or memory exhaustion

2021-06-05 Thread Shengjing Zhu
Hi Salvatore, On Sat, Jun 5, 2021 at 4:12 PM Salvatore Bonaccorso wrote: > Hi, > > The following vulnerability was published for golang-1.16. > > CVE-2021-33196[0]: How does security-tracker pull the cve data? The point release from golang appears addressing 4 cve, which are

Bug#989492: golang-1.16: CVE-2021-33196: archive/zip: malformed archive may cause panic or memory exhaustion

2021-06-05 Thread Salvatore Bonaccorso
Source: golang-1.16 Version: 1.16.4-1 Severity: grave Tags: security upstream Justification: user security hole Forwarded: https://github.com/golang/go/issues/46397 X-Debbugs-Cc: car...@debian.org, Debian Security Team Hi, The following vulnerability was published for golang-1.16.