You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
In CVE-2018-17143, the reference URL [Go Standard Library (package not identified)](Go Standard Library (package not identified)) (and possibly others) refers to something in Go.
module: std
package: Go Standard Library (package not identified)
description: |
The html package (aka x/net/html) through 2018-09-17 in Go mishandles <template><tBody><isindex/action=0>, leading to a "panic: runtime error" in inBodyIM in parse.go during an html.Parse call.
cves:
- CVE-2018-17143
links:
pr: https://go-review.googlesource.com/c/net/+/136575
context:
- https://go.dev/issue/27704
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LREEWY6KNLHRWFZ7OT4HVLMVVCGGUHON/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/UKRCI7WIOCOCD3H7NXWRGIRABTQOZOBK/
See doc/triage.md
for instructions on how to triage this report.
The text was updated successfully, but these errors were encountered:
julieqiu
changed the title
x/vulndb: potential Go vuln in "Go Standard Library (package not identified)": CVE-2018-17143
x/vulndb: potential Go vuln in net/html: CVE-2018-17143
Jan 7, 2022
julieqiu
changed the title
x/vulndb: potential Go vuln in net/html: CVE-2018-17143
x/vulndb: potential Go vuln in golang.org/x/net: CVE-2018-17143
Jan 7, 2022
In CVE-2018-17143, the reference URL [Go Standard Library (package not identified)](Go Standard Library (package not identified)) (and possibly others) refers to something in Go.
See doc/triage.md
for instructions on how to triage this report.
The text was updated successfully, but these errors were encountered: