[FREEBSD:854C2AFB-4424-11ED-AF97-ADCABF310F9B] go -- multiple vulnerabilities

Severity High
Affected Packages 2
CVEs 3

The Go project reports:

  archive/tar: unbounded memory consumption when reading
    headers
  Reader.Read did not set a limit on the maximum size of
    file headers. A maliciously crafted archive could cause
    Read to allocate unbounded amounts of memory, potentially
    causing resource exhaustion or panics. Reader.Read now
    limits the maximum size of header blocks to 1 MiB.


  net/http/httputil: ReverseProxy should not forward
    unparseable query parameters
  Requests forwarded by ReverseProxy included the raw
    query parameters from the inbound request, including
    unparseable parameters rejected by net/http. This could
    permit query parameter smuggling when a Go proxy
    forwards a parameter with an unparseable value.
  ReverseProxy will now sanitize the query parameters in
    the forwarded query when the outbound request's Form
    field is set after the ReverseProxy.Director function
    returns, indicating that the proxy has parsed the query
    parameters. Proxies which do not parse query parameters
    continue to forward the original query parameters
    unchanged.


  regexp/syntax: limit memory used by parsing regexps
  The parsed regexp representation is linear in the size
    of the input, but in some cases the constant factor can be
    as high as 40,000, making relatively small regexps consume
    much larger amounts of memory.
  Each regexp being parsed is now limited to a 256 MB
    memory footprint. Regular expressions whose
    representation would use more space than that are now
    rejected. Normal use of regular expressions is
    unaffected.
Package Affected Version
pkg:freebsd/go119 < 1.19.2
pkg:freebsd/go118 < 1.18.7
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:freebsd/go119 go119 < 1.19.2
Affected pkg:freebsd/go118 go118 < 1.18.7
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...