Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-14040

Опубликовано: 17 июн. 2020
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

The x/text package before 0.3.3 for Go has a vulnerability in encoding/unicode that could lead to the UTF-16 decoder entering an infinite loop, causing the program to crash or run out of memory. An attacker could provide a single byte to a UTF16 decoder instantiated with UseBOM or ExpectBOM to trigger an infinite loop if the String function on the Decoder is called, or the Decoder is passed to golang.org/x/text/transform.String.

A denial of service vulnerability was found in the golang.org/x/text library. A library or application must use one of the vulnerable functions, such as unicode.Transform, transform.String, or transform.Byte, to be susceptible to this vulnerability. If an attacker is able to supply specific characters or strings to the vulnerable application, there is the potential to cause an infinite loop to occur using more memory, resulting in a denial of service.

Отчет

  • OpenShift ServiceMesh (OSSM) 1.0 is Out Of Support Scope (OOSS) for Moderate and Low impact vulnerabilities. Jaeger was packaged with ServiceMesh in 1.0, and hence is also marked OOSS, but the Jaeger-Operator is a standalone product and is affected by this vulnerability.
  • Because Service Telemetry Framework does not directly use unicode.UTF16, no update will be provided at this time for STF's sg-core-container.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
A-MQ Interconnect 1amq-cert-manager-containerWill not fix
A-MQ Interconnect 1amq-interconnect-operator-containerWill not fix
OpenShift Developer Tools and Servicesjenkins-operator-containerOut of support scope
OpenShift Serverlessopenshift-serverless-clientsAffected
OpenShift Service Mesh 1jaegerOut of support scope
OpenShift Service Mesh 1jaeger-operatorOut of support scope
Red Hat Advanced Cluster Management for Kubernetes 2cert-policy-controllerAffected
Red Hat Advanced Cluster Management for Kubernetes 2configmap-watcherAffected
Red Hat Advanced Cluster Management for Kubernetes 2config-policy-controllerAffected
Red Hat Advanced Cluster Management for Kubernetes 2endpoint-component-operatorNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-835
https://bugzilla.redhat.com/show_bug.cgi?id=1853652golang.org/x/text: possibility to trigger an infinite loop in encoding/unicode could lead to crash

EPSS

Процентиль: 0%
0.00006
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 5 лет назад

The x/text package before 0.3.3 for Go has a vulnerability in encoding/unicode that could lead to the UTF-16 decoder entering an infinite loop, causing the program to crash or run out of memory. An attacker could provide a single byte to a UTF16 decoder instantiated with UseBOM or ExpectBOM to trigger an infinite loop if the String function on the Decoder is called, or the Decoder is passed to golang.org/x/text/transform.String.

CVSS3: 7.5
nvd
около 5 лет назад

The x/text package before 0.3.3 for Go has a vulnerability in encoding/unicode that could lead to the UTF-16 decoder entering an infinite loop, causing the program to crash or run out of memory. An attacker could provide a single byte to a UTF16 decoder instantiated with UseBOM or ExpectBOM to trigger an infinite loop if the String function on the Decoder is called, or the Decoder is passed to golang.org/x/text/transform.String.

CVSS3: 7.5
debian
около 5 лет назад

The x/text package before 0.3.3 for Go has a vulnerability in encoding ...

CVSS3: 7.5
github
около 4 лет назад

golang.org/x/text Infinite loop

rocky
больше 4 лет назад

Moderate: container-tools:rhel8 security, bug fix, and enhancement update

EPSS

Процентиль: 0%
0.00006
Низкий

7.5 High

CVSS3