[GO-2024-2609] Comments in display names are incorrectly handled in net/mail

Severity High
Affected Packages 2
Fixed Packages 2
CVEs 1

The ParseAddressList function incorrectly handles comments (text within
parentheses) within display names. Since this is a misalignment with conforming
address parsers, it can result in different trust decisions being made by
programs using different parsers.

Package Affected Version
pkg:golang/net/mail >= 1.22.0, < 1.21.8
pkg:golang/net/mail >= 1.22.0, < 1.22.1
Package Fixed Version
pkg:golang/net/mail = 1.21.8
pkg:golang/net/mail = 1.22.1
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Fixed pkg:golang/net/mail net mail = 1.21.8
Affected pkg:golang/net/mail net mail >= 1.22.0 < 1.21.8
Fixed pkg:golang/net/mail net mail = 1.22.1
Affected pkg:golang/net/mail net mail >= 1.22.0 < 1.22.1
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date