Lucene search

K
ubuntucveUbuntu.comUB:CVE-2023-24537
HistoryApr 06, 2023 - 12:00 a.m.

CVE-2023-24537

2023-04-0600:00:00
ubuntu.com
ubuntu.com
12
cve-2023-24537
go source code
parse functions
//line directives
integer overflow
infinite loop
zhsj
commit 99c30211b1e0b3ac4e5d32f3ae5eaf759c23195f
unix

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

0.001 Low

EPSS

Percentile

42.5%

Calling any of the Parse functions on Go source code which contains //line
directives with very large line numbers can cause an infinite loop due to
integer overflow.

Notes

Author Note
zhsj Introduced by: https://github.com/golang/go/commit/99c30211b1e0b3ac4e5d32f3ae5eaf759c23195f
OSVersionArchitecturePackageVersionFilename
ubuntu18.04noarchgolang-1.13< 1.13.8-1ubuntu1~18.04.4+esm1UNKNOWN
ubuntu20.04noarchgolang-1.13< 1.13.8-1ubuntu1.2UNKNOWN
ubuntu22.04noarchgolang-1.13< 1.13.8-1ubuntu2.22.04.2UNKNOWN
ubuntu16.04noarchgolang-1.13< 1.13.8-1ubuntu1~16.04.3+esm3UNKNOWN
ubuntu20.04noarchgolang-1.14< anyUNKNOWN
ubuntu18.04noarchgolang-1.16< 1.16.2-0ubuntu1~18.04.2+esm1UNKNOWN
ubuntu20.04noarchgolang-1.16< 1.16.2-0ubuntu1~20.04.1UNKNOWN
ubuntu22.04noarchgolang-1.17< anyUNKNOWN
ubuntu18.04noarchgolang-1.18< 1.18.1-1ubuntu1~18.04.4UNKNOWN
ubuntu20.04noarchgolang-1.18< 1.18.1-1ubuntu1~20.04.2UNKNOWN
Rows per page:
1-10 of 131

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

0.001 Low

EPSS

Percentile

42.5%