VDB
Sign up
HIGH7.5

GHSA-25xm-hr59-7c27

github.com/ulikunitz/xz fixes readUvarint Denial of Service (DoS)

Quick fix

GHSA-25xm-hr59-7c27 — github.com/ulikunitz/xz: upgrade to the fixed version with the command below.

go get github.com/ulikunitz/xz@v0.5.8

Details

### Impact

xz is a compression and decompression library focusing on the xz format completely written in Go. The function readUvarint used to read the xz container format may not terminate a loop provide malicous input.

### Patches

The problem has been fixed in release v0.5.8.

### Workarounds

Limit the size of the compressed file input to a reasonable size for your use case.

### References

The standard library had recently the same issue and got the [CVE-2020-16845](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-16845) allocated.

### For more information If you have any questions or comments about this advisory: * Open an issue in [xz](https://github.com/ulikunitz/xz/issues).

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/github.com/ulikunitz/xz
Introduced in: 0Fixed in: 0.5.8
Fixgo get github.com/ulikunitz/xz@v0.5.8

References