[GO-2024-2609] Comments in display names are incorrectly handled in net/mail
Severity
High
Affected Packages
2
Fixed Packages
2
CVEs
1
The ParseAddressList function incorrectly handles comments (text within
parentheses) within display names. Since this is a misalignment with conforming
address parsers, it can result in different trust decisions being made by
programs using different parsers.
Package | Affected Version |
---|---|
pkg:golang/net/mail | >= 1.22.0, < 1.21.8 |
pkg:golang/net/mail | >= 1.22.0, < 1.22.1 |
Package | Fixed Version |
---|---|
pkg:golang/net/mail | = 1.21.8 |
pkg:golang/net/mail | = 1.22.1 |
- ID
- GO-2024-2609
- Severity
- high
- Severity from
- CVE-2024-24784
- URL
- https://pkg.go.dev/vuln/GO-2024-2609
- Published
-
2024-03-05T21:34:11
(6 months ago) - Modified
-
2024-07-17T19:54:18
(2 months ago) - Other Advisories
-
- ALAS2-2024-2554
- ALPINE:CVE-2024-24784
- ALSA-2024:2562
- ALSA-2024:3259
- ALSA-2024:5258
- ELSA-2024-2562
- ELSA-2024-3259
- ELSA-2024-5258
- FREEBSD:B1B039EC-DBFC-11EE-9165-901B0E9408DC
- GLSA-202408-07
- RHSA-2024:2562
- RHSA-2024:3259
- RHSA-2024:5258
- RLSA-2024:2562
- SUSE-SU-2024:0800-1
- SUSE-SU-2024:0811-1
- SUSE-SU-2024:0812-1
- SUSE-SU-2024:0936-1
- SUSE-SU-2024:3089-1
- USN-6886-1
# CVE | Description | CVSS | EPSS | EPSS Trend (30 days) | Affected Products | Weaknesses | Security Advisories | Exploits | PoC | Pubblication Date | Modification Date |
---|---|---|---|---|---|---|---|---|---|---|---|
# CVE | Description | CVSS | EPSS | EPSS Trend (30 days) | Affected Products | Weaknesses | Security Advisories | PoC | Pubblication Date | Modification Date |