Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2025-22868

Опубликовано: 26 фев. 2025
Источник: debian

Описание

An attacker can pass a malicious malformed token which causes unexpected memory to be consumed during parsing.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
golang-golang-x-oauth2fixed0.27.0-1package
golang-golang-x-oauth2no-dsabookwormpackage
golang-golang-x-oauth2ignoredbullseyepackage

Примечания

  • https://pkg.go.dev/vuln/GO-2025-3488

  • https://go-review.googlesource.com/c/oauth2/+/652155

  • https://github.com/golang/go/issues/71490

Связанные уязвимости

CVSS3: 7.5
ubuntu
4 месяца назад

An attacker can pass a malicious malformed token which causes unexpected memory to be consumed during parsing.

CVSS3: 7.5
redhat
4 месяца назад

An attacker can pass a malicious malformed token which causes unexpected memory to be consumed during parsing.

CVSS3: 7.5
nvd
4 месяца назад

An attacker can pass a malicious malformed token which causes unexpected memory to be consumed during parsing.

CVSS3: 7.5
msrc
3 месяца назад

Описание отсутствует

suse-cvrf
3 месяца назад

Security update for restic