Lucene search

K
githubGitHub Advisory DatabaseGHSA-PPP9-7JFF-5VJ2
HistoryDec 26, 2022 - 6:30 a.m.

golang.org/x/text/language Out-of-bounds Read vulnerability

2022-12-2606:30:22
CWE-125
GitHub Advisory Database
github.com
26
vulnerability
golang
text
language
out-of-bounds
denial-of-service
attack
software
parsing
bcp 47

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS

0.002

Percentile

53.6%

golang.org/x/text/language in golang.org/x/text before 0.3.7 can panic with an out-of-bounds read during BCP 47 language tag parsing. Index calculation is mishandled. If parsing untrusted user input, this can be used as a vector for a denial-of-service attack.

Affected configurations

Vulners
Node
xtextRange<0.3.7
VendorProductVersionCPE
xtext*cpe:2.3:a:x:text:*:*:*:*:*:*:*:*

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS

0.002

Percentile

53.6%