Описание
Pathological inputs could cause DoS through consumePhrase when parsing an email address according to RFC 5322.
Пакеты
| Пакет | Статус | Версия исправления | Релиз | Тип |
|---|---|---|---|---|
| golang-1.25 | fixed | 1.25.10-1 | package | |
| golang-1.26 | fixed | 1.26.3-1 | package | |
| golang-1.24 | removed | package | ||
| golang-1.24 | no-dsa | trixie | package | |
| golang-1.19 | removed | package | ||
| golang-1.19 | no-dsa | bookworm | package | |
| golang-1.15 | removed | package | ||
| golang-1.15 | postponed | bullseye | package |
Примечания
https://go-review.googlesource.com/c/go/+/771520
https://github.com/golang/go/issues/78987
https://groups.google.com/g/golang-announce/c/qcCIEXso47M
EPSS
Процентиль: 53%
0.00798
Низкий
Связанные уязвимости
CVSS3: 7.5
ubuntu
3 месяца назад
Pathological inputs could cause DoS through consumePhrase when parsing an email address according to RFC 5322.
CVSS3: 7.5
redhat
3 месяца назад
Pathological inputs could cause DoS through consumePhrase when parsing an email address according to RFC 5322.
CVSS3: 7.5
nvd
3 месяца назад
Pathological inputs could cause DoS through consumePhrase when parsing an email address according to RFC 5322.
CVSS3: 7.5
github
3 месяца назад
Pathological inputs could cause DoS through consumePhrase when parsing an email address according to RFC 5322.
EPSS
Процентиль: 53%
0.00798
Низкий