Описание
golang.org/x/text/language in golang.org/x/text before 0.3.7 can panic with an out-of-bounds read during BCP 47 language tag parsing. Index calculation is mishandled. If parsing untrusted user input, this can be used as a vector for a denial-of-service attack.
Ссылки
- PatchThird Party Advisory
- Mailing ListPatchVendor Advisory
- Mailing ListThird Party Advisory
- ProductVendor Advisory
- PatchThird Party Advisory
- Mailing ListPatchVendor Advisory
- Mailing ListThird Party Advisory
- ProductVendor Advisory
Уязвимые конфигурации
EPSS
7.5 High
CVSS3
Дефекты
Связанные уязвимости
golang.org/x/text/language in golang.org/x/text before 0.3.7 can panic with an out-of-bounds read during BCP 47 language tag parsing. Index calculation is mishandled. If parsing untrusted user input, this can be used as a vector for a denial-of-service attack.
golang.org/x/text/language in golang.org/x/text before 0.3.7 can panic with an out-of-bounds read during BCP 47 language tag parsing. Index calculation is mishandled. If parsing untrusted user input, this can be used as a vector for a denial-of-service attack.
golang.org/x/text/language in golang.org/x/text before 0.3.7 can panic ...
golang.org/x/text/language Out-of-bounds Read vulnerability
EPSS
7.5 High
CVSS3