Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-17075

Опубликовано: 26 сент. 2018
Источник: redhat
CVSS3: 5.3
EPSS Низкий

Описание

The html package (aka x/net/html) before 2018-07-13 in Go mishandles "in frameset" insertion mode, leading to a "panic: runtime error" for html.Parse of <template>, <template>, or <template>. This is related to HTMLTreeBuilder.cpp in WebKit.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Ceph Storage 2grafanaNot affected
Red Hat Ceph Storage 3grafanaNot affected
Red Hat Developer ToolskomposeOut of support scope
Red Hat Enterprise Linux 7golang-googlecode-netNot affected
Red Hat OpenShift Container Platform 3.10atomic-openshiftNot affected
Red Hat OpenShift Container Platform 3.11atomic-openshiftNot affected
Red Hat OpenShift Container Platform 3.2atomic-openshiftNot affected
Red Hat OpenShift Container Platform 3.3atomic-openshiftNot affected
Red Hat OpenShift Container Platform 3.4atomic-openshiftNot affected
Red Hat OpenShift Container Platform 3.5atomic-openshiftNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-20
https://bugzilla.redhat.com/show_bug.cgi?id=1633041golang-org-x-net-html: Mishandle of "in frameset" causes runtime panic in html.Parse() via crafted html

EPSS

Процентиль: 72%
0.00716
Низкий

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 7 лет назад

The html package (aka x/net/html) before 2018-07-13 in Go mishandles "in frameset" insertion mode, leading to a "panic: runtime error" for html.Parse of <template><object>, <template><applet>, or <template><marquee>. This is related to HTMLTreeBuilder.cpp in WebKit.

CVSS3: 7.5
nvd
больше 7 лет назад

The html package (aka x/net/html) before 2018-07-13 in Go mishandles "in frameset" insertion mode, leading to a "panic: runtime error" for html.Parse of <template><object>, <template><applet>, or <template><marquee>. This is related to HTMLTreeBuilder.cpp in WebKit.

CVSS3: 7.5
debian
больше 7 лет назад

The html package (aka x/net/html) before 2018-07-13 in Go mishandles " ...

CVSS3: 7.5
github
больше 3 лет назад

golang.org/x/net/html NULL Pointer Dereference vulnerability

EPSS

Процентиль: 72%
0.00716
Низкий

5.3 Medium

CVSS3