CVE-2020-28851

Description

In x/text in Go 1.15.4, an index out of range panic occurs in language.ParseAcceptLanguage while parsing the -u- extension. (x/text/language is supposed to be able to parse an HTTP Accept-Language header.)

Risk Information

Base Score
7.5
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS Score
Exploitation Probability
0.138

Associated Vulnerability

VulnerabilityOS Platform
Git-lfs update (ELSA-2022-7129) git-lfs-2.13.3-3.el8_6.x86_64.rpmLinux
Supplementary Go text-related libraries (USN-5873-1) golang-x-text-dev_0.0~git20170627.0.6353ef0-1ubuntu2.1_all.debLinux
Supplementary Go text-related libraries (USN-5873-1) golang-golang-x-text-dev_0.3.2-4ubuntu0.1_all.debLinux
Supplementary Go text-related libraries (USN-5873-1) golang-golang-x-text-dev_0.3.7-1ubuntu0.20.04.1_all.debLinux
Supplementary Go text-related libraries (USN-5873-1) golang-golang-x-text-dev_0.3.7-1ubuntu0.22.10.1_all.debLinux
Supplementary Go text-related libraries (USN-5873-1) golang-golang-x-text-dev_0.0~git20170627.0.6353ef0-1ubuntu2.1_all.debLinux
git-lfs security and bug fix update (RLSA-2022:7129) git-lfs-2.13.3-3.el8_6.x86_64.rpmLinux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234