CVE-2024-24789

Updated: 2025-01-31 22:26:46.287914

Description:

The archive/zip package's handling of certain types of invalid zip files differs from the behavior of most zip implementations. This misalignment could be exploited to create an zip file with contents that vary depending on the implementation reading the file. The archive/zip package now rejects files containing these errors.


Links NIST CIRCL RHEL Ubuntu

Severity

Severity Score
CVSS Version 2.x 0
CVSS Version 3.x MEDIUM 5.5

Status

OS name Project name Version Score Severity Status Errata Last updated

Statement

AlmaLinux 9.2 ESU grafana 9.0.9 5.5 MEDIUM Needs Triage 2025-05-08 02:47:07
AlmaLinux 9.2 ESU golang 1.19.13 5.5 MEDIUM In Testing 2025-05-18 05:05:33
AlmaLinux 9.2 ESU podman 4.4.1 5.5 MEDIUM Needs Triage 2025-05-16 22:43:10