Input validation error in Go programming language - CVE-2021-41772

 

Input validation error in Go programming language - CVE-2021-41772

Published: August 4, 2022


Vulnerability identifier: #VU66120
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-41772
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to insufficient validation of user-supplied input in archive/zip Reader.Open. A remote attacker can pass specially crafted ZIP archive containing an invalid name or an empty filename field to the application and perform a denial of service (DoS) attack.


Affected software

Go programming language
Gentoo Linux
Amazon Linux AMI
Fedora
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Anolis OS
SUSE Linux Enterprise Module for Development Tools
ObjectScale
Astronomer with IBM
watsonx Orchestrate Cartridge for IBM Cloud Pak for Data
IBM Netezza for Cloud Pak for Data
Dell PowerProtect Cyber Recovery
QRadar Suite
Splunk Enterprise
Red Hat OpenShift Container Platform
Migration Toolkit for Containers
OpenShift Serverless Client
IBM Robotic Process Automation
Netcool Operations Insight
Red Hat OpenShift Serverless
openshift-serverless-clients (Red Hat package)
delve
go1.16
go1.16-doc
go1.16-race
golang
go1.17
go1.17-race
go1.17-doc
go-toolset
golang-race
golang-bin
golang-docs
golang-misc
golang-src
golang-tests
Brownfield Connectivity - Gateway

How to mitigate CVE-2021-41772

Install updates from vendor's website.

Go programming language - addressed in versions 1.16.10, 1.17.3
ObjectScale - update to 1.3.0
Astronomer with IBM - update to 1.0.1
QRadar Suite - update to 1.10.17.0
watsonx Orchestrate Cartridge for IBM Cloud Pak for Data - update to 5.3
Red Hat OpenShift Container Platform - update to 4.12.4
Splunk Enterprise - addressed in versions 8.2.12, 9.0.6, 9.1.1
IBM Robotic Process Automation - update to 21.0.3.1
Red Hat OpenShift Serverless - update to 1
openshift-serverless-clients (Red Hat package) - update to 1.1.0-2.el8
Netcool Operations Insight - update to 1.6.6
Migration Toolkit for Containers - update to 1.7.1
delve - update to 1.7.2-1
Brownfield Connectivity - Gateway - update to 1.10.1
go1.16 - update to 1.16.10-1.32.1
go1.16-doc - update to 1.16.10-1.32.1
go1.16-race - update to 1.16.10-1.32.1
golang - addressed in versions 1.16.11-1.fc34, 1.16.11-1.fc35, 1.16.13-2.el7
golang - addressed in versions 1.16.15-1.37, 1.19.3-2
go1.17 - update to 1.17.3-1.9.1
go1.17-race - update to 1.17.3-1.9.1
go1.17-doc - update to 1.17.3-1.9.1
go-toolset - update to 1.17.7-1
golang - update to 1.17.7-1
golang-race - update to 1.17.7-1
golang-bin - update to 1.17.7-1
golang-docs - update to 1.17.7-1
golang-misc - update to 1.17.7-1
golang-src - update to 1.17.7-1
golang-tests - update to 1.17.7-1
OpenShift Serverless Client - update to 1.22.0
IBM Netezza for Cloud Pak for Data - update to 11.2.3.3
Dell PowerProtect Cyber Recovery - update to 19.14.0.1

External References

Related Security Bulletins