AIKIDO-2024-10434

github.com/cosnicolaou/pbzip2 is vulnerable to Integer Overflow

49

Medium

github.com/cosnicolaou/pbzip2 go

AIKIDO-2024-10434: github.com/cosnicolaou/pbzip2 is vulnerable to Integer Overflow in versions 1.0.0 - 1.0.3.

Integer Overflow
Vuln in 1.0.0 - 1.0.3
Fixed in 1.0.4
No CVE available
TL;DR

Affected versions of the package are vulnerable to several integer overflows as described in GOSEC's G115 rule.

Who does this affect?

You're affected if you are using a version which is within vulnerability ranges

How can it be fixed?

Upgrade github.com/cosnicolaou/pbzip2 library to patch version.

Background info

Link to vendor website

Logo
© 2024 Aikido Security BV | BE0792914919
🇪🇺 Grauwpoort 1, 9000 Ghent, Belgium
🇺🇸 95 Third St, 2nd Fl, San Francisco, CA 94103, US