[GO-2022-0522] Stack exhaustion on crafted paths in path/filepath

Severity High
Affected Packages 2
Fixed Packages 2
CVEs 1

Calling Glob on a path which contains a large number of path separators can
cause a panic due to stack exhaustion.

Package Affected Version
pkg:golang/path/filepath >= 1.18.3, < 1.17.12
pkg:golang/path/filepath >= 1.18.3, < 1.18.4
Package Fixed Version
pkg:golang/path/filepath = 1.17.12
pkg:golang/path/filepath = 1.18.4
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Fixed pkg:golang/path/filepath path filepath = 1.17.12
Affected pkg:golang/path/filepath path filepath >= 1.18.3 < 1.17.12
Fixed pkg:golang/path/filepath path filepath = 1.18.4
Affected pkg:golang/path/filepath path filepath >= 1.18.3 < 1.18.4
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...