Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2022-1962

Опубликовано: 10 авг. 2022
Источник: debian
EPSS Низкий

Описание

Uncontrolled recursion in the Parse functions in go/parser before Go 1.17.12 and Go 1.18.4 allow an attacker to cause a panic due to stack exhaustion via deeply nested types or declarations.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
golang-1.19fixed1.19~rc2-1package
golang-1.18fixed1.18.4-1package
golang-1.17fixed1.17.13-1package
golang-1.15removedpackage
golang-1.15no-dsabullseyepackage
golang-1.11removedpackage
golang-1.11postponedbusterpackage

Примечания

  • https://go.dev/issue/53616

  • https://github.com/golang/go/commit/695be961d57508da5a82217f7415200a11845879 (go1.19rc2)

  • https://github.com/golang/go/commit/0d1615b23f9a558aa0a1957b4c81596220eb8ec4 (go1.18.4)

  • https://github.com/golang/go/commit/ba8788ebcead55e99e631c6a1157ad7b35535d11 (go1.17.12)

EPSS

Процентиль: 0%
0.00004
Низкий

Связанные уязвимости

CVSS3: 5.5
ubuntu
почти 3 года назад

Uncontrolled recursion in the Parse functions in go/parser before Go 1.17.12 and Go 1.18.4 allow an attacker to cause a panic due to stack exhaustion via deeply nested types or declarations.

CVSS3: 5.5
redhat
около 3 лет назад

Uncontrolled recursion in the Parse functions in go/parser before Go 1.17.12 and Go 1.18.4 allow an attacker to cause a panic due to stack exhaustion via deeply nested types or declarations.

CVSS3: 5.5
nvd
почти 3 года назад

Uncontrolled recursion in the Parse functions in go/parser before Go 1.17.12 and Go 1.18.4 allow an attacker to cause a panic due to stack exhaustion via deeply nested types or declarations.

CVSS3: 5.5
msrc
почти 3 года назад

Описание отсутствует

CVSS3: 5.5
github
почти 3 года назад

Uncontrolled recursion in the Parse functions in go/parser before Go 1.17.12 and Go 1.18.4 allow an attacker to cause a panic due to stack exhaustion via deeply nested types or declarations.

EPSS

Процентиль: 0%
0.00004
Низкий