[FREEBSD:A5C64F6F-2AF3-11EF-A77E-901B0E9408DC] go -- multiple vulnerabilities

Severity Critical
Affected Packages 2
CVEs 2

The Go project reports:

  archive/zip: mishandling of corrupt central directory record
  The archive/zip package's handling of certain types of
  invalid zip files differed from the behavior of most zip
  implementations. This misalignment could be exploited to
  create an zip file with contents that vary depending on the
  implementation reading the file. The archive/zip package now
  rejects files containing these errors.


  net/netip: unexpected behavior from Is methods for
  IPv4-mapped IPv6 addresses
  The various Is methods (IsPrivate, IsLoopback, etc) did
  not work as expected for IPv4-mapped IPv6 addresses,
  returning false for addresses which would return true in
  their traditional IPv4 forms.
Package Affected Version
pkg:freebsd/go122 < 1.22.4
pkg:freebsd/go121 < 1.21.11
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:freebsd/go122 go122 < 1.22.4
Affected pkg:freebsd/go121 go121 < 1.21.11
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...