Vulnerability Report: GO-2021-0096
- CVE-2020-8945, GHSA-m6wg-2mwg-4rfq
- Affects: github.com/proglottis/gpgme
- Published: Apr 14, 2021
- Modified: May 20, 2024
Due to improper setting of finalizers, memory passed to C may be freed before it is used, leading to crashes due to memory corruption or possible code execution.
Affected Packages
-
PathGo VersionsSymbols
-
before v0.1.1all symbols
Aliases
References
- https://github.com/proglottis/gpgme/pull/23
- https://github.com/proglottis/gpgme/commit/92153bcb59bd2f511e502262c46c7bd660e21733
- https://vuln.go.dev/ID/GO-2021-0096.json
Credits
- Ulrich Obergfell
Feedback
See anything missing or incorrect?
Suggest an edit to this report.