CVE-2023-24537

CVSS V2 None CVSS V3 None
Description
Calling any of the Parse functions on Go source code which contains //line directives with very large line numbers can cause an infinite loop due to integer overflow.
Overview
  • CVE ID
  • CVE-2023-24537
  • Assigner
  • security@golang.org
  • Vulnerability Status
  • Analyzed
  • Published Version
  • 2023-04-06T16:15:07
  • Last Modified Date
  • 2023-04-13T19:09:08
CPE Configuration (Product)
CPE Vulnerable Operator Version Start Version End
cpe:2.3:a:golang:go:*:*:*:*:*:*:*:* 1 OR 1.19.8
cpe:2.3:a:golang:go:*:*:*:*:*:*:*:* 1 OR 1.20.0 1.20.3
References
Reference URL Reference Tags
https://go.dev/cl/482078 Issue Tracking Patch
https://go.dev/issue/59180 Issue Tracking Patch
https://groups.google.com/g/golang-announce/c/Xdv6JL9ENs8 Mailing List Vendor Advisory
https://pkg.go.dev/vuln/GO-2023-1702 Vendor Advisory
History
Created Old Value New Value Data Type Notes
2023-04-17 04:17:09 Added to TrackCVE
2023-04-17 04:17:12 Weakness Enumeration new