Количество 8
Количество 8

CVE-2020-14040
The x/text package before 0.3.3 for Go has a vulnerability in encoding/unicode that could lead to the UTF-16 decoder entering an infinite loop, causing the program to crash or run out of memory. An attacker could provide a single byte to a UTF16 decoder instantiated with UseBOM or ExpectBOM to trigger an infinite loop if the String function on the Decoder is called, or the Decoder is passed to golang.org/x/text/transform.String.

CVE-2020-14040
The x/text package before 0.3.3 for Go has a vulnerability in encoding/unicode that could lead to the UTF-16 decoder entering an infinite loop, causing the program to crash or run out of memory. An attacker could provide a single byte to a UTF16 decoder instantiated with UseBOM or ExpectBOM to trigger an infinite loop if the String function on the Decoder is called, or the Decoder is passed to golang.org/x/text/transform.String.

CVE-2020-14040
The x/text package before 0.3.3 for Go has a vulnerability in encoding/unicode that could lead to the UTF-16 decoder entering an infinite loop, causing the program to crash or run out of memory. An attacker could provide a single byte to a UTF16 decoder instantiated with UseBOM or ExpectBOM to trigger an infinite loop if the String function on the Decoder is called, or the Decoder is passed to golang.org/x/text/transform.String.
CVE-2020-14040
The x/text package before 0.3.3 for Go has a vulnerability in encoding ...
GHSA-5rcv-m4m3-hfh7
golang.org/x/text Infinite loop

RLSA-2020:4694
Moderate: container-tools:rhel8 security, bug fix, and enhancement update
ELSA-2020-4694
ELSA-2020-4694: container-tools:ol8 security, bug fix, and enhancement update (MODERATE)
ELSA-2020-3665
ELSA-2020-3665: go-toolset:ol8 security update (MODERATE)
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
---|---|---|---|---|
![]() | CVE-2020-14040 The x/text package before 0.3.3 for Go has a vulnerability in encoding/unicode that could lead to the UTF-16 decoder entering an infinite loop, causing the program to crash or run out of memory. An attacker could provide a single byte to a UTF16 decoder instantiated with UseBOM or ExpectBOM to trigger an infinite loop if the String function on the Decoder is called, or the Decoder is passed to golang.org/x/text/transform.String. | CVSS3: 7.5 | 0% Низкий | около 5 лет назад |
![]() | CVE-2020-14040 The x/text package before 0.3.3 for Go has a vulnerability in encoding/unicode that could lead to the UTF-16 decoder entering an infinite loop, causing the program to crash or run out of memory. An attacker could provide a single byte to a UTF16 decoder instantiated with UseBOM or ExpectBOM to trigger an infinite loop if the String function on the Decoder is called, or the Decoder is passed to golang.org/x/text/transform.String. | CVSS3: 7.5 | 0% Низкий | около 5 лет назад |
![]() | CVE-2020-14040 The x/text package before 0.3.3 for Go has a vulnerability in encoding/unicode that could lead to the UTF-16 decoder entering an infinite loop, causing the program to crash or run out of memory. An attacker could provide a single byte to a UTF16 decoder instantiated with UseBOM or ExpectBOM to trigger an infinite loop if the String function on the Decoder is called, or the Decoder is passed to golang.org/x/text/transform.String. | CVSS3: 7.5 | 0% Низкий | около 5 лет назад |
CVE-2020-14040 The x/text package before 0.3.3 for Go has a vulnerability in encoding ... | CVSS3: 7.5 | 0% Низкий | около 5 лет назад | |
GHSA-5rcv-m4m3-hfh7 golang.org/x/text Infinite loop | CVSS3: 7.5 | 0% Низкий | около 4 лет назад | |
![]() | RLSA-2020:4694 Moderate: container-tools:rhel8 security, bug fix, and enhancement update | больше 4 лет назад | ||
ELSA-2020-4694 ELSA-2020-4694: container-tools:ol8 security, bug fix, and enhancement update (MODERATE) | больше 4 лет назад | |||
ELSA-2020-3665 ELSA-2020-3665: go-toolset:ol8 security update (MODERATE) | почти 5 лет назад |
Уязвимостей на страницу