This repository has been archived by the owner on Jan 3, 2023. It is now read-only.
CVE-2020-16845 (High) detected in github.com/ulikunitz/xz-v0.5.6 #5
Labels
security vulnerability
Security vulnerability detected by WhiteSource
CVE-2020-16845 - High Severity Vulnerability
Vulnerable Library - github.com/ulikunitz/xz-v0.5.6
Pure golang package for reading and writing xz-compressed files
Library home page: https://proxy.golang.org/github.com/ulikunitz/xz/@v/v0.5.6.zip
Dependency Hierarchy:
Vulnerability Details
Go before 1.13.15 and 14.x before 1.14.7 can have an infinite read loop in ReadUvarint and ReadVarint in encoding/binary via invalid inputs.
Publish Date: 2020-08-06
URL: CVE-2020-16845
CVSS 3 Score Details (7.5)
Base Score Metrics:
Suggested Fix
Type: Upgrade version
Origin: GHSA-q6gq-997w-f55g
Release Date: 2020-08-06
Fix Resolution: go1.13.15,go1.14.7,github.com/ulikunitz/xz - v0.5.8
Step up your Open Source Security Game with Mend here
The text was updated successfully, but these errors were encountered: