Tatiana Bradley | f1409b0 | 2023-05-24 14:02:12 -0400 | [diff] [blame] | 1 | id: GO-2022-0192 |
Damien Neil | b5cb765 | 2022-08-18 15:09:12 -0700 | [diff] [blame] | 2 | modules: |
Tatiana Bradley | 82175fd | 2023-05-31 17:04:08 -0400 | [diff] [blame] | 3 | - module: golang.org/x/net |
| 4 | versions: |
| 5 | - fixed: 0.0.0-20180925071336-cf3bd585ca2a |
| 6 | vulnerable_at: 0.0.0-20180921000356-2f5d2388922f |
| 7 | packages: |
| 8 | - package: golang.org/x/net/html |
| 9 | symbols: |
| 10 | - parser.resetInsertionMode |
| 11 | derived_symbols: |
| 12 | - Parse |
| 13 | - ParseFragment |
Tatiana Bradley | 00566bd | 2023-05-09 12:26:34 -0400 | [diff] [blame] | 14 | summary: Improper input validation in golang.org/x/net/html |
Tatiana Bradley | ccdac2d | 2023-06-22 13:27:05 -0400 | [diff] [blame] | 15 | description: |- |
Damien Neil | b91c206 | 2022-06-29 12:06:31 -0700 | [diff] [blame] | 16 | The Parse function can panic on some invalid inputs. |
| 17 | |
| 18 | For example, the Parse function panics on the input |
| 19 | "<math><template><mo><template>". |
Damien Neil | 95a417d | 2022-08-17 15:39:45 -0700 | [diff] [blame] | 20 | published: 2022-07-01T20:11:34Z |
Damien Neil | b91c206 | 2022-06-29 12:06:31 -0700 | [diff] [blame] | 21 | cves: |
Tatiana Bradley | 82175fd | 2023-05-31 17:04:08 -0400 | [diff] [blame] | 22 | - CVE-2018-17142 |
Tatiana Bradley | 2fcfeff | 2023-02-08 13:03:32 -0500 | [diff] [blame] | 23 | ghsas: |
Tatiana Bradley | 82175fd | 2023-05-31 17:04:08 -0400 | [diff] [blame] | 24 | - GHSA-2wp2-chmh-r934 |
Tatiana Bradley | 0910814 | 2023-05-18 16:23:32 -0400 | [diff] [blame] | 25 | credits: |
Tatiana Bradley | 82175fd | 2023-05-31 17:04:08 -0400 | [diff] [blame] | 26 | - '@tr3ee' |
Damien Neil | 00e94d7 | 2022-08-26 14:59:35 -0700 | [diff] [blame] | 27 | references: |
Tatiana Bradley | 82175fd | 2023-05-31 17:04:08 -0400 | [diff] [blame] | 28 | - fix: https://go.dev/cl/136875 |
| 29 | - fix: https://go.googlesource.com/net/+/cf3bd585ca2a5a21b057abd8be7eea2204af89d0 |
| 30 | - report: https://go.dev/issue/27702 |