Skip to content

golang CVE-2020-16845

Moderate
etungsten published GHSA-h382-mj64-43m3 Aug 17, 2020

Package

golang (bottlerocket)

Affected versions

< 0.5.0

Patched versions

0.5.0

Description

Go before 1.13.15 and 14.x before 1.14.7 can have an infinite read loop in ReadUvarint and ReadVarint in encoding/binary via invalid inputs.

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-16845
https://groups.google.com/forum/#!topic/golang-announce/NyPIaucMgXo

Severity

Moderate

CVE ID

CVE-2020-16845

Weaknesses

No CWEs