VDB
GO-2023-2071
GO-2023-2071
PUBLISHED
CVSS 8.699999809265137 HIGH
Sender can cause a receiver to overwrite files during ZIP extraction in Croc in github.com/schollz/croc
Risk Scores
CVSS 4.0
8.699999809265137
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| github.com | schollz/croc/v6 | 0, 0 |
| wolfi | croc | 0, 0, 0 |
| github.com | schollz/croc | 0, 0 |
| chainguard | croc | 0 |
| github.com | schollz/croc/v8 | 0, 0 |
| github.com | schollz/croc/v9 | 0, 0 |
Timeline
- Aug 21, 2024 CVE Published
- Feb 4, 2026 CVE Updated
- May 18, 2026 Security Advisory
References
- http://www.openwall.com/lists/oss-security/2023/09/21/5 url
- https://github.com/advisories/GHSA-8c8w-f7wp-2jr2 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2023-43616 advisory
- https://www.openwall.com/lists/oss-security/2023/09/08/2 url
- https://github.com/schollz/croc/commit/4929635eb875d2304e9415b8f4aa62af9e1a2339 fix
- https://github.com/schollz/croc/pull/698 fix
- https://github.com/schollz/croc/issues/594 discussion