Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2021-27918

Опубликовано: 11 мар. 2021
Источник: debian
EPSS Низкий

Описание

encoding/xml in Go before 1.15.9 and 1.16.x before 1.16.1 has an infinite loop if a custom TokenReader (for xml.NewTokenDecoder) returns EOF in the middle of an element. This can occur in the Decode, DecodeElement, or Skip method.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
golang-1.16fixed1.16.3-1package
golang-1.15fixed1.15.9-1package
golang-1.11removedpackage
golang-1.11postponedbusterpackage
golang-1.8removedpackage
golang-1.8postponedstretchpackage
golang-1.7removedpackage
golang-1.7postponedstretchpackage

Примечания

  • https://groups.google.com/g/golang-announce/c/MfiLYjG-RAw

  • https://github.com/golang/go/issues/44913

EPSS

Процентиль: 6%
0.00026
Низкий

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 4 лет назад

encoding/xml in Go before 1.15.9 and 1.16.x before 1.16.1 has an infinite loop if a custom TokenReader (for xml.NewTokenDecoder) returns EOF in the middle of an element. This can occur in the Decode, DecodeElement, or Skip method.

CVSS3: 7.5
redhat
больше 4 лет назад

encoding/xml in Go before 1.15.9 and 1.16.x before 1.16.1 has an infinite loop if a custom TokenReader (for xml.NewTokenDecoder) returns EOF in the middle of an element. This can occur in the Decode, DecodeElement, or Skip method.

CVSS3: 7.5
nvd
больше 4 лет назад

encoding/xml in Go before 1.15.9 and 1.16.x before 1.16.1 has an infinite loop if a custom TokenReader (for xml.NewTokenDecoder) returns EOF in the middle of an element. This can occur in the Decode, DecodeElement, or Skip method.

CVSS3: 7.5
msrc
больше 4 лет назад

Описание отсутствует

suse-cvrf
около 4 лет назад

Security update for go1.15

EPSS

Процентиль: 6%
0.00026
Низкий