github.com/nwaples/rardecode versions <=2.1.1 fail to restrict the dictionary size when reading large RAR dictionary sizes, which allows an attacker to provide a specially crafted RAR file and cause Denial of Service via an Out Of Memory Crash.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| github.com/nwaples/rardecode/v2(Go) | 0 | 2.2.0 | N/A |
| github.com/nwaples/rardecode(Go) | 0 | N/A | N/A |
CVSS Metrics