Vulnerability Report: GO-2023-1702
standard library- CVE-2023-24537
- Affects: go/scanner
- Published: Apr 05, 2023
- Modified: May 20, 2024
Calling any of the Parse functions on Go source code which contains //line directives with very large line numbers can cause an infinite loop due to integer overflow.
Affected Packages
-
PathGo VersionsSymbols
-
before go1.19.8, from go1.20.0-0 before go1.20.3
Aliases
References
- https://go.dev/issue/59180
- https://go.dev/cl/482078
- https://groups.google.com/g/golang-announce/c/Xdv6JL9ENs8
- https://vuln.go.dev/ID/GO-2023-1702.json
Credits
- Philippe Antoine (Catena cyber)
Feedback
See anything missing or incorrect?
Suggest an edit to this report.