Уязвимость выхода за пределы границ буфера в debug/macho в Go
Описание
В Go обнаружена уязвимость в модуле debug/macho
(для функций Open
или OpenFat
). Она связана с доступом к области памяти за пределами конца буфера (out-of-bounds slice situation).
Затронутые версии ПО
- Go до версии 1.16.10
- Go версии 1.17.x до 1.17.3
Тип уязвимости
Выход за пределы границ среза (out-of-bounds slice)
Ссылки
- Vendor Advisory
- Mailing ListThird Party Advisory
- Mailing ListThird Party Advisory
- Third Party Advisory
- Third Party Advisory
- Third Party Advisory
- Vendor Advisory
- Mailing ListThird Party Advisory
- Mailing ListThird Party Advisory
- Third Party Advisory
- Third Party Advisory
- Third Party Advisory
Уязвимые конфигурации
Одно из
Одно из
EPSS
7.5 High
CVSS3
5 Medium
CVSS2
Дефекты
Связанные уязвимости
ImportedSymbols in debug/macho (for Open or OpenFat) in Go before 1.16.10 and 1.17.x before 1.17.3 Accesses a Memory Location After the End of a Buffer, aka an out-of-bounds slice situation.
ImportedSymbols in debug/macho (for Open or OpenFat) in Go before 1.16.10 and 1.17.x before 1.17.3 Accesses a Memory Location After the End of a Buffer, aka an out-of-bounds slice situation.
ImportedSymbols in debug/macho (for Open or OpenFat) in Go before 1.16 ...
ImportedSymbols in debug/macho (for Open or OpenFat) in Go before 1.16.10 and 1.17.x before 1.17.3 Accesses a Memory Location After the End of a Buffer, aka an out-of-bounds slice situation.
EPSS
7.5 High
CVSS3
5 Medium
CVSS2