Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:33334
HistoryDec 14, 2021 - 8:52 p.m.

Invalid I/O Calculation

2021-12-1420:52:34
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
16
golang
vulnerability
i/o calculation
unix
misdirected
syscall.forkexec

EPSS

0.005

Percentile

77.6%

golang-1.15:sid is vulnerable to invalid I/O calculation. The attack is possible when a Go program running on a Unix system is out of file descriptors and calls syscall.ForkExec and its can close file descriptor 0 when it fails, its misdirected the I/O such as writing network traffic intended for one connection to a different connection, or content intended for one file to a different one.