← Back to CVE List

CVE-2022-2879

Published: 2022-10-14T15:15Z
Last Modified: 2024-11-21T07:01Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
Reader.Read does not set a limit on the maximum size of file headers. A maliciously crafted archive could cause Read to allocate unbounded amounts of memory, potentially causing resource exhaustion or panics. After fix, Reader.Read limits the maximum size of header blocks to 1 MiB. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt