Name
CVE-2024-24789
Description
The archive/zip package's handling of certain types of invalid zip files differs from the behavior of most zip implementations. This misalignment could be exploited to create an zip file with contents that vary depending on the implementation reading the file. The archive/zip package now rejects files containing these errors.
CWEs
Published Date
Updated Date
Workaround
-
Advisories
https://go.dev/issue/66869Issue Tracking
https://pkg.go.dev/vuln/GO-2024-2888Third Party Advisory
https://go.dev/issue/66869Issue Tracking
https://pkg.go.dev/vuln/GO-2024-2888Third Party Advisory
Analysis#
Vulnerability Ratings#
5.5
CVSSv31
5.3
CVSSv31
NaN
other
Others affected components#
Name
Project
Project Version
Version
Status
openwrt
master
1.24.13-r1
Not Affected
openwrt
master
1.26.4-r1
Not Affected
openwrt
openwrt-25.12
1.24.13-r1
Not Affected
openwrt
openwrt-25.12
1.26.4-r1
Not Affected
yocto
master
1.26.4
Not Affected
yocto
master
1.26.4
Not Affected
yocto
scarthgap
1.22.12
Not Affected
yocto
scarthgap
1.22.12
Not Affected