blob: fb877e40ed858bf32fb25084fd70ac90fd9434db [file] [log] [blame]
package = "archive/zip"
stdlib = true
description = """
Using Reader.Open on an archive containing a file with a path
prefixed by "../" will cause a panic due to a stack overflow.
"""
cve = "CVE-2021-27919"
symbols = ["toValidName"]
published = "2021-04-14T12:00:00Z"
[[versions]]
introduced = "go1.16"
fixed = "go1.16.1"
[links]
commit = "https://github.com/golang/go/commit/cd3b4ca9f20fd14187ed4cdfdee1a02ea87e5cd8"
pr = "https://go-review.googlesource.com/c/go/+/300489"
context = ["https://github.com/golang/go/issues/44916"]