Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2020-16845

Опубликовано: 06 авг. 2020
Источник: debian
EPSS Низкий

Описание

Go before 1.13.15 and 14.x before 1.14.7 can have an infinite read loop in ReadUvarint and ReadVarint in encoding/binary via invalid inputs.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
golang-1.15fixed1.15~rc2-1package
golang-1.14fixed1.14.7-1package
golang-1.11removedpackage
golang-1.8removedpackage
golang-1.7removedpackage

Примечания

  • https://groups.google.com/forum/#!topic/golang-announce/NyPIaucMgXo

  • https://github.com/golang/go/issues/40618

  • Fixed in 1.15~rc2, 1.14.7, 1.13.15

EPSS

Процентиль: 26%
0.00084
Низкий

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 5 лет назад

Go before 1.13.15 and 14.x before 1.14.7 can have an infinite read loop in ReadUvarint and ReadVarint in encoding/binary via invalid inputs.

CVSS3: 7.5
redhat
почти 5 лет назад

Go before 1.13.15 and 14.x before 1.14.7 can have an infinite read loop in ReadUvarint and ReadVarint in encoding/binary via invalid inputs.

CVSS3: 7.5
nvd
почти 5 лет назад

Go before 1.13.15 and 14.x before 1.14.7 can have an infinite read loop in ReadUvarint and ReadVarint in encoding/binary via invalid inputs.

CVSS3: 7.5
msrc
почти 5 лет назад

Описание отсутствует

suse-cvrf
почти 5 лет назад

Security update for go1.13

EPSS

Процентиль: 26%
0.00084
Низкий