Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-17143

Опубликовано: 26 сент. 2018
Источник: redhat
CVSS3: 5.3

Описание

The html package (aka x/net/html) through 2018-09-17 in Go mishandles <template><isindex/action=0>, leading to a "panic: runtime error" in inBodyIM in parse.go during an html.Parse call.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Ceph Storage 2grafanaNot affected
Red Hat Ceph Storage 3grafanaNot affected
Red Hat Developer ToolskomposeOut of support scope
Red Hat Enterprise Linux 7golang-googlecode-netNot affected
Red Hat OpenShift Container Platform 3.10atomic-openshiftNot affected
Red Hat OpenShift Container Platform 3.11atomic-openshiftNot affected
Red Hat OpenShift Container Platform 3.2atomic-openshiftNot affected
Red Hat OpenShift Container Platform 3.3atomic-openshiftNot affected
Red Hat OpenShift Container Platform 3.4atomic-openshiftNot affected
Red Hat OpenShift Container Platform 3.5atomic-openshiftNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-20
https://bugzilla.redhat.com/show_bug.cgi?id=1633036golang-org-x-net-html: Runtime panic in html.Parse() via crafted html

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 7 лет назад

The html package (aka x/net/html) through 2018-09-17 in Go mishandles <template><tBody><isindex/action=0>, leading to a "panic: runtime error" in inBodyIM in parse.go during an html.Parse call.

CVSS3: 7.5
nvd
больше 7 лет назад

The html package (aka x/net/html) through 2018-09-17 in Go mishandles <template><tBody><isindex/action=0>, leading to a "panic: runtime error" in inBodyIM in parse.go during an html.Parse call.

CVSS3: 7.5
debian
больше 7 лет назад

The html package (aka x/net/html) through 2018-09-17 in Go mishandles ...

CVSS3: 7.5
github
больше 3 лет назад

golang.org/x/net/html has Improper Restriction of Operations within the Bounds of a Memory Buffer

5.3 Medium

CVSS3