Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-17847

Опубликовано: 01 окт. 2018
Источник: redhat
CVSS3: 5.3
EPSS Низкий

Описание

The html package (aka x/net/html) through 2018-09-25 in Go mishandles <template></template>, leading to a "panic: runtime error" (index out of range) in (*nodeStack).pop in node.go, called from (*parser).clearActiveFormattingElements, during an html.Parse call.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Ceph Storage 2grafanaNot affected
Red Hat Ceph Storage 3grafanaNot affected
Red Hat Developer ToolskomposeOut of support scope
Red Hat Enterprise Linux 7golang-googlecode-netNot affected
Red Hat OpenShift Container Platform 3.10atomic-openshiftNot affected
Red Hat OpenShift Container Platform 3.11atomic-openshiftNot affected
Red Hat OpenShift Container Platform 3.2atomic-openshiftNot affected
Red Hat OpenShift Container Platform 3.3atomic-openshiftNot affected
Red Hat OpenShift Container Platform 3.4atomic-openshiftNot affected
Red Hat OpenShift Container Platform 3.5atomic-openshiftNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-20
https://bugzilla.redhat.com/show_bug.cgi?id=1639116golang-org-x-net-html: index out of range in (*nodeStack).pop in node.go causes runtime panic during html.Parse() call

EPSS

Процентиль: 75%
0.00906
Низкий

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 7 лет назад

The html package (aka x/net/html) through 2018-09-25 in Go mishandles <svg><template><desc><t><svg></template>, leading to a "panic: runtime error" (index out of range) in (*nodeStack).pop in node.go, called from (*parser).clearActiveFormattingElements, during an html.Parse call.

CVSS3: 7.5
nvd
больше 7 лет назад

The html package (aka x/net/html) through 2018-09-25 in Go mishandles <svg><template><desc><t><svg></template>, leading to a "panic: runtime error" (index out of range) in (*nodeStack).pop in node.go, called from (*parser).clearActiveFormattingElements, during an html.Parse call.

CVSS3: 7.5
debian
больше 7 лет назад

The html package (aka x/net/html) through 2018-09-25 in Go mishandles ...

CVSS3: 7.5
github
больше 3 лет назад

golang.org/x/net/html has Improper Restriction of Operations within the Bounds of a Memory Buffer

EPSS

Процентиль: 75%
0.00906
Низкий

5.3 Medium

CVSS3