Lucene search

K
redhatRedHatRHSA-2024:6912
HistorySep 23, 2024 - 1:15 a.m.

(RHSA-2024:6912) Moderate: go-toolset:rhel8 security update

2024-09-2301:15:39
access.redhat.com
rhsa-2024-6912
moderate
go-toolset
rhel8
security update
go programming language
net/http
encoding/gob
denial of service
improper 100-continue handling
stack exhaustion
cve-2024-24791
cve-2024-34156
cvss score
references section

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Go Toolset provides the Go programming language tools and libraries. Go is alternatively known as golang.

Security Fix(es):

  • net/http: Denial of service due to improper 100-continue handling in net/http (CVE-2024-24791)

  • encoding/gob: golang: Calling Decoder.Decode on a message which contains deeply nested structures can cause a panic due to stack exhaustion (CVE-2024-34156)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H