5
CVSSv2

CVE-2018-17846

Published: 01/10/2018 Updated: 07/11/2023
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

The html package (aka x/net/html) through 2018-09-25 in Go mishandles <table><math><select><mi><select></table>, leading to an infinite loop during an html.Parse call because inSelectIM and inSelectInTableIM do not comply with a specification.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

golang net

fedoraproject fedora 28

fedoraproject fedora 29

Vendor Advisories

Debian Bug report logs - #911795 CVE-2018-17846 / CVE-2018-17847 / CVE-2018-17848 Package: src:golang-golang-x-net-dev; Maintainer for src:golang-golang-x-net-dev is Debian Go Packaging Team &lt;team+pkg-go@trackerdebianorg&gt;; Reported by: Moritz Muehlenhoff &lt;jmm@debianorg&gt; Date: Wed, 24 Oct 2018 21:21:01 UTC Severity ...
The html package (aka x/net/html) through 2018-09-25 in Go mishandles &lt;table&gt;&lt;math&gt;&lt;select&gt;&lt;mi&gt;&lt;select&gt;&lt;/table&gt;, leading to an infinite loop during an htmlParse call because inSelectIM and inSelectInTableIM do not comply with a specification ...