We found results for “”
CVE-2023-23626
Good to know:
Date: February 9, 2023
go-bitfield is a simple bitfield package for the go language aiming to be more performant that the standard library. When feeding untrusted user input into the size parameter of "NewBitfield" and "FromBytes" functions, an attacker can trigger "panic"s. This happen when the "size" is a not a multiple of "8" or is negative. There were already a note in the "NewBitfield" documentation, however known users of this package are subject to this issue. Users are advised to upgrade. Users unable to upgrade should ensure that "size" is a multiple of 8 before calling "NewBitfield" or "FromBytes".
Language: Go
Severity Score
Related Resources (6)
Severity Score
Weakness Type (CWE)
Top Fix
CVSS v3.1
| Base Score: |
|
|---|---|
| Attack Vector (AV): | NETWORK |
| Attack Complexity (AC): | HIGH |
| Privileges Required (PR): | NONE |
| User Interaction (UI): | NONE |
| Scope (S): | UNCHANGED |
| Confidentiality (C): | NONE |
| Integrity (I): | NONE |
| Availability (A): | HIGH |
Vulnerabilities
Projects
Contact Us


