Description
Reader.Read does not set a limit on the maximum size of file headers. A maliciously crafted archive could cause Read to allocate unbounded amounts of memory, potentially causing resource exhaustion or panics. After fix, Reader.Read limits the maximum size of header blocks to 1 MiB.
Affected products
- Go standard library / archive/tar0 – 1.18.7
- Go standard library / archive/tar1.19.0-0 – 1.19.2
Updated 8m ago · 8 sources