ALT-PU-2022-1707-1
Closed vulnerabilities
BDU:2022-01896
Уязвимость компонентов net.ParseIP, net.ParseCIDR языка программирования Go, позволяющая нарушителю оказать воздействие на целостность данных
Modified: 2024-11-21
CVE-2021-29923
Go before 1.17 does not properly consider extraneous zero characters at the beginning of an IP address octet, which (in some situations) allows attackers to bypass access control that is based on IP addresses, because of unexpected octal interpretation. This affects net.ParseIP and net.ParseCIDR.
- https://defcon.org/html/defcon-29/dc-29-speakers.html#kaoudis
- https://defcon.org/html/defcon-29/dc-29-speakers.html#kaoudis
- https://github.com/golang/go/issues/30999
- https://github.com/golang/go/issues/30999
- https://github.com/golang/go/issues/43389
- https://github.com/golang/go/issues/43389
- https://github.com/sickcodes/security/blob/master/advisories/SICK-2021-016.md
- https://github.com/sickcodes/security/blob/master/advisories/SICK-2021-016.md
- https://golang.org/pkg/net/#ParseCIDR
- https://golang.org/pkg/net/#ParseCIDR
- https://go-review.googlesource.com/c/go/+/325829/
- https://go-review.googlesource.com/c/go/+/325829/
- FEDORA-2022-17d004ed71
- FEDORA-2022-17d004ed71
- GLSA-202208-02
- GLSA-202208-02
- https://www.oracle.com/security-alerts/cpujan2022.html
- https://www.oracle.com/security-alerts/cpujan2022.html
Modified: 2024-11-21
CVE-2022-24675
encoding/pem in Go before 1.17.9 and 1.18.x before 1.18.1 has a Decode stack overflow via a large amount of PEM data.
- https://cert-portal.siemens.com/productcert/pdf/ssa-744259.pdf
- https://cert-portal.siemens.com/productcert/pdf/ssa-744259.pdf
- https://groups.google.com/g/golang-announce
- https://groups.google.com/g/golang-announce
- https://groups.google.com/g/golang-announce/c/oecdBNLOml8
- https://groups.google.com/g/golang-announce/c/oecdBNLOml8
- FEDORA-2022-a49babed75
- FEDORA-2022-a49babed75
- FEDORA-2022-c0f780ecf1
- FEDORA-2022-c0f780ecf1
- FEDORA-2022-e46e6e8317
- FEDORA-2022-e46e6e8317
- FEDORA-2022-30c5ed5625
- FEDORA-2022-30c5ed5625
- FEDORA-2022-ba365d3703
- FEDORA-2022-ba365d3703
- FEDORA-2022-fae3ecee19
- FEDORA-2022-fae3ecee19
- GLSA-202208-02
- GLSA-202208-02
- https://security.netapp.com/advisory/ntap-20220915-0010/
- https://security.netapp.com/advisory/ntap-20220915-0010/
Modified: 2024-11-21
CVE-2022-27536
Certificate.Verify in crypto/x509 in Go 1.18.x before 1.18.1 can be caused to panic on macOS when presented with certain malformed certificates. This allows a remote TLS server to cause a TLS client to panic.
- https://cert-portal.siemens.com/productcert/pdf/ssa-744259.pdf
- https://cert-portal.siemens.com/productcert/pdf/ssa-744259.pdf
- https://groups.google.com/g/golang-announce
- https://groups.google.com/g/golang-announce
- https://groups.google.com/g/golang-announce/c/oecdBNLOml8
- https://groups.google.com/g/golang-announce/c/oecdBNLOml8
- GLSA-202208-02
- GLSA-202208-02
- https://security.netapp.com/advisory/ntap-20230309-0001/
- https://security.netapp.com/advisory/ntap-20230309-0001/
Modified: 2024-11-21
CVE-2022-28327
The generic P-256 feature in crypto/elliptic in Go before 1.17.9 and 1.18.x before 1.18.1 allows a panic via long scalar input.
- https://cert-portal.siemens.com/productcert/pdf/ssa-744259.pdf
- https://cert-portal.siemens.com/productcert/pdf/ssa-744259.pdf
- https://groups.google.com/g/golang-announce
- https://groups.google.com/g/golang-announce
- https://groups.google.com/g/golang-announce/c/oecdBNLOml8
- https://groups.google.com/g/golang-announce/c/oecdBNLOml8
- FEDORA-2022-a49babed75
- FEDORA-2022-a49babed75
- FEDORA-2022-c0f780ecf1
- FEDORA-2022-c0f780ecf1
- FEDORA-2022-53f0c619c5
- FEDORA-2022-53f0c619c5
- FEDORA-2022-e46e6e8317
- FEDORA-2022-e46e6e8317
- FEDORA-2022-30c5ed5625
- FEDORA-2022-30c5ed5625
- FEDORA-2022-ba365d3703
- FEDORA-2022-ba365d3703
- FEDORA-2022-fae3ecee19
- FEDORA-2022-fae3ecee19
- GLSA-202208-02
- GLSA-202208-02
- https://security.netapp.com/advisory/ntap-20220915-0010/
- https://security.netapp.com/advisory/ntap-20220915-0010/