Intel

AIKIDO-2024-10434

github.com/cosnicolaou/pbzip2 is vulnerable to Integer Overflow

Integer Overflow Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Nov 8, 2024

49

Medium Risk

This Affects:

gogithub.com/cosnicolaou/pbzip2
1.0.0 - 1.0.3
Fixed in 1.0.4
Are you affected? Scan for Free

TL;DR

Affected versions of the package are vulnerable to several integer overflows, as identified by GOSEC's G115 rule. This rule specifically detects potential vulnerabilities arising from improper handling of integer operations, where the value of an integer may exceed the allowed range for the type, causing unexpected behavior or security flaws.

Who does this affect?

You are affected if you are using a version which is within vulnerability ranges

Background info

github.com/cosnicolaou/pbzip2 is vulnerable to Integer Overflow in versions 1.0.0 - 1.0.3.

How to fix this

Upgrade the github.com/cosnicolaou/pbzip2 library to the patch version.