Unrated severityNVD Advisory· Published Aug 2, 2021· Updated Aug 3, 2024
CVE-2021-33196
CVE-2021-33196
Description
In archive/zip in Go before 1.15.13 and 1.16.x before 1.16.5, a crafted file count (in an archive's header) can cause a NewReader or OpenReader panic.
Affected products
29- Go/archive/zipdescription
- osv-coords28 versionspkg:bitnami/golangpkg:rpm/almalinux/delvepkg:rpm/almalinux/golangpkg:rpm/almalinux/golang-binpkg:rpm/almalinux/golang-docspkg:rpm/almalinux/golang-miscpkg:rpm/almalinux/golang-racepkg:rpm/almalinux/golang-srcpkg:rpm/almalinux/golang-testspkg:rpm/almalinux/go-toolsetpkg:rpm/opensuse/go1.15&distro=openSUSE%20Leap%2015.2pkg:rpm/opensuse/go1.15&distro=openSUSE%20Leap%2015.3pkg:rpm/opensuse/go1.15&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/go1.16&distro=openSUSE%20Leap%2015.3pkg:rpm/opensuse/go1.16&distro=openSUSE%20Tumbleweedpkg:rpm/suse/go1.15&distro=SUSE%20Enterprise%20Storage%206pkg:rpm/suse/go1.15&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP1-ESPOSpkg:rpm/suse/go1.15&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP1-LTSSpkg:rpm/suse/go1.15&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Development%20Tools%2015%20SP2pkg:rpm/suse/go1.15&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Development%20Tools%2015%20SP3pkg:rpm/suse/go1.15&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP1-BCLpkg:rpm/suse/go1.15&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP1-LTSSpkg:rpm/suse/go1.15&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP1pkg:rpm/suse/go1.15&distro=SUSE%20Manager%20Proxy%204.0pkg:rpm/suse/go1.15&distro=SUSE%20Manager%20Retail%20Branch%20Server%204.0pkg:rpm/suse/go1.15&distro=SUSE%20Manager%20Server%204.0pkg:rpm/suse/go1.16&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Development%20Tools%2015%20SP2pkg:rpm/suse/go1.16&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Development%20Tools%2015%20SP3
< 1.15.13+ 27 more
- (no CPE)range: < 1.15.13
- (no CPE)range: < 1.7.2-1.module_el8.6.0+2736+ec10aba8
- (no CPE)range: < 1.17.7-1.module_el8.6.0+2736+ec10aba8
- (no CPE)range: < 1.17.7-1.module_el8.6.0+2736+ec10aba8
- (no CPE)range: < 1.17.7-1.module_el8.6.0+2736+ec10aba8
- (no CPE)range: < 1.17.7-1.module_el8.6.0+2736+ec10aba8
- (no CPE)range: < 1.17.7-1.module_el8.6.0+2736+ec10aba8
- (no CPE)range: < 1.17.7-1.module_el8.6.0+2736+ec10aba8
- (no CPE)range: < 1.17.7-1.module_el8.6.0+2736+ec10aba8
- (no CPE)range: < 1.17.7-1.module_el8.6.0+2736+ec10aba8
- (no CPE)range: < 1.15.13-lp152.20.1
- (no CPE)range: < 1.15.13-1.33.1
- (no CPE)range: < 1.15.15-1.2
- (no CPE)range: < 1.16.5-1.17.1
- (no CPE)range: < 1.16.8-1.1
- (no CPE)range: < 1.15.13-1.33.1
- (no CPE)range: < 1.15.13-1.33.1
- (no CPE)range: < 1.15.13-1.33.1
- (no CPE)range: < 1.15.13-1.33.1
- (no CPE)range: < 1.15.13-1.33.1
- (no CPE)range: < 1.15.13-1.33.1
- (no CPE)range: < 1.15.13-1.33.1
- (no CPE)range: < 1.15.13-1.33.1
- (no CPE)range: < 1.15.13-1.33.1
- (no CPE)range: < 1.15.13-1.33.1
- (no CPE)range: < 1.15.13-1.33.1
- (no CPE)range: < 1.16.5-1.17.1
- (no CPE)range: < 1.16.5-1.17.1
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
6- security.gentoo.org/glsa/202208-02mitrevendor-advisory
- lists.debian.org/debian-lts-announce/2022/01/msg00016.htmlmitremailing-list
- lists.debian.org/debian-lts-announce/2022/01/msg00017.htmlmitremailing-list
- lists.debian.org/debian-lts-announce/2023/04/msg00021.htmlmitremailing-list
- groups.google.com/g/golang-announcemitre
- groups.google.com/g/golang-announce/c/RgCMkAEQjSImitre
News mentions
0No linked articles in our index yet.