Lucene search

K
mageiaGentoo FoundationMGASA-2022-0377
HistoryOct 19, 2022 - 2:14 a.m.

Updated golang packages fix security vulnerability

2022-10-1902:14:56
Gentoo Foundation
advisories.mageia.org
29
golang
security
vulnerabilities
regex memory
memory consumption
unparseable query

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

EPSS

0.002

Percentile

60.1%

regexp/syntax: limit memory used by parsing regexps (CVE-2022-41715) archive/tar: unbounded memory consumption when reading headers (CVE-2022-2879) net/http/httputil: ReverseProxy should not forward unparseable query parameters (CVE-2022-2880)

OSVersionArchitecturePackageVersionFilename
Mageia8noarchgolang< 1.18.7-1golang-1.18.7-1.mga8

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

EPSS

0.002

Percentile

60.1%