[ALPINE:CVE-2023-45290] go vulnerability

Affected Packages 7
Fixed Packages 7
CVEs 1

[From CVE-2023-45290] When parsing a multipart form (either explicitly with Request.ParseMultipartForm or implicitly with Request.FormValue, Request.PostFormValue, or Request.FormFile), limits on the total size of the parsed form were not applied to the memory consumed while reading a single form line. This permits a maliciously crafted input containing very long lines to cause allocation of arbitrarily large amounts of memory, potentially leading to memory exhaustion. With fix, the ParseMultipartForm function now correctly limits the maximum size of form lines.

Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Fixed pkg:apk/alpine/go?arch=x86_64&distro=alpine-3.19 alpine go = 1.21.8-r0 alpine-3.19 x86_64
Affected pkg:apk/alpine/go?arch=x86_64&distro=alpine-3.19 alpine go < 1.21.8-r0 alpine-3.19 x86_64
Fixed pkg:apk/alpine/go?arch=x86&distro=alpine-3.19 alpine go = 1.21.8-r0 alpine-3.19 x86
Affected pkg:apk/alpine/go?arch=x86&distro=alpine-3.19 alpine go < 1.21.8-r0 alpine-3.19 x86
Fixed pkg:apk/alpine/go?arch=s390x&distro=alpine-3.19 alpine go = 1.21.8-r0 alpine-3.19 s390x
Affected pkg:apk/alpine/go?arch=s390x&distro=alpine-3.19 alpine go < 1.21.8-r0 alpine-3.19 s390x
Fixed pkg:apk/alpine/go?arch=ppc64le&distro=alpine-3.19 alpine go = 1.21.8-r0 alpine-3.19 ppc64le
Affected pkg:apk/alpine/go?arch=ppc64le&distro=alpine-3.19 alpine go < 1.21.8-r0 alpine-3.19 ppc64le
Fixed pkg:apk/alpine/go?arch=armv7&distro=alpine-3.19 alpine go = 1.21.8-r0 alpine-3.19 armv7
Affected pkg:apk/alpine/go?arch=armv7&distro=alpine-3.19 alpine go < 1.21.8-r0 alpine-3.19 armv7
Fixed pkg:apk/alpine/go?arch=armhf&distro=alpine-3.19 alpine go = 1.21.8-r0 alpine-3.19 armhf
Affected pkg:apk/alpine/go?arch=armhf&distro=alpine-3.19 alpine go < 1.21.8-r0 alpine-3.19 armhf
Fixed pkg:apk/alpine/go?arch=aarch64&distro=alpine-3.19 alpine go = 1.21.8-r0 alpine-3.19 aarch64
Affected pkg:apk/alpine/go?arch=aarch64&distro=alpine-3.19 alpine go < 1.21.8-r0 alpine-3.19 aarch64
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...