Improper resource allocation In golang.org/x/text
Description
golang.org/x/text Infinite loop Go version v0.3.3 of the x/text package fixes a vulnerability in encoding/unicode that could lead to the UTF-16 decoder entering an infinite loop, causing the program to crash or run out of memory. An attacker could provide a single byte to a UTF16 decoder instantiated with UseBOM or ExpectBOM to trigger an infinite loop if the String function on the Decoder is called, or the Decoder is passed to golang.org/x/text/transform.String.
Specific Go Packages Affected
golang.org/x/text/encoding/unicode golang.org/x/text/transform
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Component | Affected version | Patched versions |
|---|---|---|---|
go | 0.3.3 | ||
debian 12 | 0.3.3-1 | ||
debian 11 | 0.3.3-1 | ||
debian 14 | 0.3.3-1 | ||
debian 13 | 0.3.3-1 | ||
go | 0.3.3 | ||
rpm rhel8 | - | - | |
rpm rhel8 | 0:1.13.15-1.module+el8.2.0+7662+fa98b974 | ||
rpm rhel7 | - | - | |
rpm rhel8 | - | - |
1-10 of 11
10
Aliases
References