VulnerabilityModified
CVE-2024-24789
The archive/zip package's handling of certain types of invalid zip files differs from the behavior of most zip implementations.
MEDIUM 5.5EPSS 0.45%
Does this matter?
Lower severity and a low EPSS score (0.45%). Track it; it rarely justifies an emergency change on its own.
Description
The archive/zip package's handling of certain types of invalid zip files differs from the behavior of most zip implementations. This misalignment could be exploited to create an zip file with contents that vary depending on the implementation reading the file. The archive/zip package now rejects files containing these errors.
- CVSS 3.1
- 5.5 MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
- EPSS
- 0.45% probability · 38th percentile
- CISA KEV
- Not listed
- Affected
- golang/go
- Source
- security@golang.org
References
- http://www.openwall.com/lists/oss-security/2024/06/04/1Mailing List
- https://go.dev/cl/585397Patch
- https://go.dev/issue/66869Issue Tracking, Patch
- https://groups.google.com/g/golang-announce/c/XbxouI9gY7k/m/TuoGEhxIEwAJRelease Notes
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/U5YAEIA6IUHUNGJ7AIXXPQT6D2GYENX7/
- https://pkg.go.dev/vuln/GO-2024-2888Third Party Advisory
- http://www.openwall.com/lists/oss-security/2024/06/04/1Mailing List
- https://go.dev/cl/585397Patch
- https://go.dev/issue/66869Issue Tracking, Patch
- https://groups.google.com/g/golang-announce/c/XbxouI9gY7k/m/TuoGEhxIEwAJRelease Notes
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/U5YAEIA6IUHUNGJ7AIXXPQT6D2GYENX7/
- https://pkg.go.dev/vuln/GO-2024-2888Third Party Advisory
- https://security.netapp.com/advisory/ntap-20250131-0008/
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.