[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

250053

 
 

909

 
 

195940

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

ALAS2-2022-1776 --- golang

ID: oval:org.secpod.oval:def:1700888Date: (C)2022-05-04   (M)2023-12-11
Class: PATCHFamily: unix




A validation flaw was found in golang. When invoking functions from WASM modules built using GOARCH=wasm GOOS=js, passing very large arguments can cause portions of the module to be overwritten with data from the arguments. The highest threat from this vulnerability is to integrity. An out of bounds read vulnerability was found in debug/macho of the Go standard library. When using the debug/macho standard library and malformed binaries are parsed using Open or OpenFat, it can cause golang to attempt to read outside of a slice causing a panic when calling ImportedSymbols. An attacker can use this vulnerability to craft a file which causes an application using this library to crash resulting in a denial of service. A vulnerability was found in archive/zip of the Go standard library. Applications written in Go where Reader.Open can panic when parsing a crafted ZIP archive containing completely invalid names or an empty filename argument. There's an uncontrolled resource consumption flaw in golang's net/http library in the canonicalHeader function. An attacker who submits specially crafted requests to applications linked with net/http's http2 functionality could cause excessive resource consumption that could lead to a denial of service or otherwise impact to system performance and resources. There's a flaw in golang's syscall.ForkExec interface. An attacker who manages to first cause a file descriptor exhaustion for the process, then cause syscall.ForkExec to be called repeatedly, could compromise data integrity and/or confidentiality in a somewhat uncontrolled way in programs linked with and using syscall.ForkExec

Platform:
Amazon Linux 2
Product:
golang
Reference:
ALAS2-2022-1776
CVE-2021-38297
CVE-2021-41771
CVE-2021-41772
CVE-2021-44716
CVE-2021-44717
CVE-2022-23773
CVE-2022-23772
CVE-2022-24921
CVE-2021-39293
CVE-2022-23806
CVE    10
CVE-2021-38297
CVE-2021-39293
CVE-2021-41771
CVE-2021-44717
...
CPE    2
cpe:/a:golang:golang
cpe:/o:amazon:linux:2

© SecPod Technologies