Описание
regexp.Compile in Go before 1.16.15 and 1.17.x before 1.17.8 allows stack exhaustion via a deeply nested expression.
Пакеты
Пакет | Статус | Версия исправления | Релиз | Тип |
---|---|---|---|---|
golang-1.18 | fixed | 1.18~rc1-1 | package | |
golang-1.17 | fixed | 1.17.8-1 | package | |
golang-1.15 | removed | package | ||
golang-1.15 | fixed | 1.15.15-1~deb11u4 | bullseye | package |
golang-1.11 | removed | package | ||
golang-1.8 | removed | package | ||
golang-1.7 | removed | package |
Примечания
https://github.com/golang/go/issues/51112
https://groups.google.com/g/golang-announce/c/RP1hfrBYVuk
https://github.com/golang/go/commit/ac071634c487eb6ac5422652de3c7c18fba7c522 (go1.17.8)
https://github.com/golang/go/commit/452f24ae94f38afa3704d4361d91d51218405c0a (go1.18rc1)
EPSS
Процентиль: 1%
0.00014
Низкий
Связанные уязвимости
CVSS3: 7.5
ubuntu
больше 3 лет назад
regexp.Compile in Go before 1.16.15 and 1.17.x before 1.17.8 allows stack exhaustion via a deeply nested expression.
CVSS3: 7.5
redhat
больше 3 лет назад
regexp.Compile in Go before 1.16.15 and 1.17.x before 1.17.8 allows stack exhaustion via a deeply nested expression.
CVSS3: 7.5
nvd
больше 3 лет назад
regexp.Compile in Go before 1.16.15 and 1.17.x before 1.17.8 allows stack exhaustion via a deeply nested expression.
EPSS
Процентиль: 1%
0.00014
Низкий