MEDIUM5.3
GHSA-rwvp-r38j-9rgg
rardecode: DoS risk due to unrestricted RAR dictionary sizes
Quick fix
GHSA-rwvp-r38j-9rgg — github.com/nwaples/rardecode/v2: upgrade to the fixed version with the command below.
go get github.com/nwaples/rardecode/v2@v2.2.0Details
rardecode versions <= 2.1.1 fail to restrict the dictionary size when reading large RAR dictionary sizes, which allows an attacker to provide a specially crafted RAR file and cause Denial of Service via an Out Of Memory Crash.
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/nwaples/rardecode/v2
Introduced in:
0Fixed in: 2.2.0Fix
go get github.com/nwaples/rardecode/v2@v2.2.0Go/github.com/nwaples/rardecode
Introduced in:
0No fixed version published yet for github.com/nwaples/rardecode (go modules). Pin to a known-safe version or switch to an alternative.