Уязвимость неконтролируемого расхода памяти в функции "Rat.SetString" из библиотеки "math/big" в Go
Описание
В функции Rat.SetString
из библиотеки math/big
в языке программирования Go обнаружена уязвимость переполнения, которая приводит к неконтролируемому расходу памяти.
Затронутые версии ПО
- Go до релиза 1.16.14
- Go версии 1.17.x перед релизом 1.17.7
Тип уязвимости
Неконтролируемый расход памяти (Uncontrolled Memory Consumption)
Ссылки
- Release NotesVendor Advisory
- Mailing ListThird Party Advisory
- Mailing ListThird Party Advisory
- Third Party Advisory
- Third Party Advisory
- Third Party Advisory
- Release NotesVendor Advisory
- Mailing ListThird Party Advisory
- Mailing ListThird Party Advisory
- Third Party Advisory
- Third Party Advisory
- Third Party Advisory
Уязвимые конфигурации
Одно из
Одно из
EPSS
7.5 High
CVSS3
7.8 High
CVSS2
Дефекты
Связанные уязвимости
Rat.SetString in math/big in Go before 1.16.14 and 1.17.x before 1.17.7 has an overflow that can lead to Uncontrolled Memory Consumption.
Rat.SetString in math/big in Go before 1.16.14 and 1.17.x before 1.17.7 has an overflow that can lead to Uncontrolled Memory Consumption.
Rat.SetString in math/big in Go before 1.16.14 and 1.17.x before 1.17. ...
Rat.SetString in math/big in Go before 1.16.14 and 1.17.x before 1.17.7 has an overflow that can lead to Uncontrolled Memory Consumption.
EPSS
7.5 High
CVSS3
7.8 High
CVSS2