goblin is vulnerable to Integer Overflow
66
Medium Risk
Affected versions of this package are vulnerable to an integer overflow in the pe.tls.tlsdata.parse_with_opts function due to insufficient bounds checking when parsing Thread Local Storage data. An attacker can exploit this by providing a maliciously crafted PE file with either an excessively large offset or by triggering an integer overflow in the calculation of the Relative Virtual Address, bypassing the offset size checks. It could lead to out-of-bounds memory access, potentially causing a denial-of-service or information disclosure if the application processes unintended memory regions.
You are affected if you are using a version that falls within the vulnerable range.
goblin is vulnerable to Integer Overflow in versions 0.8.2 - 0.9.3.
Upgrade the goblin library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant