Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2020-14040

Опубликовано: 17 июн. 2020
Источник: debian

Описание

The x/text package before 0.3.3 for Go has a vulnerability in encoding/unicode that could lead to the UTF-16 decoder entering an infinite loop, causing the program to crash or run out of memory. An attacker could provide a single byte to a UTF16 decoder instantiated with UseBOM or ExpectBOM to trigger an infinite loop if the String function on the Decoder is called, or the Decoder is passed to golang.org/x/text/transform.String.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
golang-golang-x-textfixed0.3.3-1package
golang-x-textremovedpackage
golang-x-textpostponedbusterpackage
golang-x-textno-dsastretchpackage

Примечания

  • https://github.com/golang/go/issues/39491

  • https://go.googlesource.com/text/+/23ae387dee1f90d29a23c0e87ee0b46038fbed0e

  • https://groups.google.com/forum/#!topic/golang-announce/bXVeAmGOqz0

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 5 лет назад

The x/text package before 0.3.3 for Go has a vulnerability in encoding/unicode that could lead to the UTF-16 decoder entering an infinite loop, causing the program to crash or run out of memory. An attacker could provide a single byte to a UTF16 decoder instantiated with UseBOM or ExpectBOM to trigger an infinite loop if the String function on the Decoder is called, or the Decoder is passed to golang.org/x/text/transform.String.

CVSS3: 7.5
redhat
около 5 лет назад

The x/text package before 0.3.3 for Go has a vulnerability in encoding/unicode that could lead to the UTF-16 decoder entering an infinite loop, causing the program to crash or run out of memory. An attacker could provide a single byte to a UTF16 decoder instantiated with UseBOM or ExpectBOM to trigger an infinite loop if the String function on the Decoder is called, or the Decoder is passed to golang.org/x/text/transform.String.

CVSS3: 7.5
nvd
около 5 лет назад

The x/text package before 0.3.3 for Go has a vulnerability in encoding/unicode that could lead to the UTF-16 decoder entering an infinite loop, causing the program to crash or run out of memory. An attacker could provide a single byte to a UTF16 decoder instantiated with UseBOM or ExpectBOM to trigger an infinite loop if the String function on the Decoder is called, or the Decoder is passed to golang.org/x/text/transform.String.

CVSS3: 7.5
github
около 4 лет назад

golang.org/x/text Infinite loop

rocky
больше 4 лет назад

Moderate: container-tools:rhel8 security, bug fix, and enhancement update