7.5
CVSSv3

CVE-2020-16845

Published: 06/08/2020 Updated: 07/11/2023
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 446
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

Go prior to 1.13.15 and 14.x prior to 1.14.7 can have an infinite read loop in ReadUvarint and ReadVarint in encoding/binary via invalid inputs.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

golang go

opensuse leap 15.1

opensuse leap 15.2

debian debian linux 9.0

debian debian linux 10.0

fedoraproject fedora 31

fedoraproject fedora 32

Vendor Advisories

Debian Bug report logs - #988942 CVE-2021-20291 Package: golang-github-containers-image; Maintainer for golang-github-containers-image is Debian Go Packaging Team <team+pkg-go@trackerdebianorg>; Source for golang-github-containers-image is src:golang-github-containers-image (PTS, buildd, popcon) Reported by: Moritz Muehlen ...
Debian Bug report logs - #988243 golang-github-ulikunitz-xz: CVE-2021-29482 Package: src:golang-github-ulikunitz-xz; Maintainer for src:golang-github-ulikunitz-xz is Debian Go Packaging Team <team+pkg-go@trackerdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Sat, 8 May 2021 14:18:01 UTC Sev ...
Multiple security issues were discovered in the implementation of the Go programming language, which could result in denial of service and the P-224 curve implementation could generate incorrect outputs For the stable distribution (buster), these problems have been fixed in version 1116-1+deb10u4 We recommend that you upgrade your golang-111 p ...
The x/text package before 033 for Go has a vulnerability in encoding/unicode that could lead to the UTF-16 decoder entering an infinite loop, causing the program to crash or run out of memory An attacker could provide a single byte to a UTF16 decoder instantiated with UseBOM or ExpectBOM to trigger an infinite loop if the String function on the ...
The x/text package before 033 for Go has a vulnerability in encoding/unicode that could lead to the UTF-16 decoder entering an infinite loop, causing the program to crash or run out of memory An attacker could provide a single byte to a UTF16 decoder instantiated with UseBOM or ExpectBOM to trigger an infinite loop if the String function on the ...
Synopsis Moderate: OpenShift Serverless 190 release and security update Type/Severity Security Advisory: Moderate Topic OpenShift Serverless 190 release and security update is now availableRed Hat Product Security has rated this update as having a security impact of Moderate A Common Vulnerability Sco ...
Synopsis Moderate: go-toolset:rhel8 security update Type/Severity Security Advisory: Moderate Topic An update for the go-toolset:rhel8 module is now available for Red Hat Enterprise Linux 8Red Hat Product Security has rated this update as having a security impact of Moderate A Common Vulnerability Scoring ...
Synopsis Moderate: OpenShift Container Platform 4520 packages and golang security update Type/Severity Security Advisory: Moderate Topic Red Hat OpenShift Container Platform release 4520 is now available with updates to packages and images that fix several bugsThis release also includes a security upda ...
Synopsis Low: OpenShift Virtualization 242 Images Type/Severity Security Advisory: Low Topic Red Hat OpenShift Virtualization release 242 is now available with updates to packages and images that fix several bugs and add enhancementsRed Hat Product Security has rated this update as having a security im ...
Synopsis Low: OpenShift Container Platform 466 security update Type/Severity Security Advisory: Low Topic An update for faq is now available for Red Hat OpenShift Container Platform 46Red Hat Product Security has rated this update as having a security impact of Low A Common Vulnerability Scoring System ...
Synopsis Moderate: OpenShift Container Platform 461 package security update Type/Severity Security Advisory: Moderate Topic An update for jenkins-2-plugins, openshift-clients, podman, runc, and skopeo is now available for Red Hat OpenShift Container Platform 46Red Hat Product Security has rated this upd ...
Synopsis Moderate: Red Hat OpenShift Container Storage 46 bug fix and enhancement update Type/Severity Security Advisory: Moderate Topic An update for mcg is now available for Red Hat OpenShift Container Storage 460 on RHEL-8Red Hat Product Security has rated this update as having a security impact of M ...
Synopsis Moderate: go-toolset-113-golang security and bug fix update Type/Severity Security Advisory: Moderate Topic An update for go-toolset-113 and go-toolset-113-golang is now available for Red Hat Developer ToolsRed Hat Product Security has rated this update as having a security impact of Moderate ...
Synopsis Low: Red Hat OpenShift Service Mesh 1111 security update Type/Severity Security Advisory: Low Topic An update is now available for OpenShift Service Mesh 11Red Hat Product Security has rated this update as having a security impact of Low A Common Vulnerability Scoring System (CVSS) base score, ...
Synopsis Moderate: OpenShift Container Platform 4520 bug fix and golang security update Type/Severity Security Advisory: Moderate Topic Red Hat OpenShift Container Platform release 4520 is now available with updates to packages and images that fix several bugsThis release includes a security update for ...
Synopsis Moderate: Red Hat OpenShift Container Storage 460 security, bug fix, enhancement update Type/Severity Security Advisory: Moderate Topic Updated images are now available for Red Hat OpenShift Container Storage 460 on Red Hat Enterprise Linux 8Red Hat Product Security has rated this update as ha ...
Synopsis Important: Migration Toolkit for Containers (MTC) 174 security and bug fix update Type/Severity Security Advisory: Important Topic The Migration Toolkit for Containers (MTC) 174 is now availableRed Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability Scoring System (CVSS) ba ...