Description
The x/text package before 0.3.3 for Go has a vulnerability in encoding/unicode that could lead to the UTF-16 decoder entering an infinite loop, causing the program to crash or run out of memory. An attacker could provide a single byte to a UTF16 decoder instantiated with UseBOM or ExpectBOM to trigger an infinite loop if the String function on the Decoder is called, or the Decoder is passed to golang.org/x/text/transform.String.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-0962 | The x/text package before 0.3.3 for Go has a vulnerability in encoding/unicode that could lead to the UTF-16 decoder entering an infinite loop, causing the program to crash or run out of memory. An attacker could provide a single byte to a UTF16 decoder instantiated with UseBOM or ExpectBOM to trigger an infinite loop if the String function on the Decoder is called, or the Decoder is passed to golang.org/x/text/transform.String. |
Github GHSA |
GHSA-5rcv-m4m3-hfh7 | golang.org/x/text Infinite loop |
Ubuntu USN |
USN-5873-1 | Go Text vulnerabilities |
References
History
Wed, 16 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Sun, 08 Sep 2024 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:/a:redhat:acm:2.2::el7 |
Mon, 19 Aug 2024 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:/a:redhat:acm:2.2::el8 |
Subscriptions
Fedoraproject
Subscribe
Fedora
Subscribe
Golang
Subscribe
Text
Subscribe
Redhat
Subscribe
3scale Amp
Subscribe
Acm
Subscribe
Container Native Virtualization
Subscribe
Devtools
Subscribe
Enterprise Linux
Subscribe
Integration
Subscribe
Jaeger
Subscribe
Jboss Fuse
Subscribe
Openshift
Subscribe
Openshift Container Storage
Subscribe
Quay
Subscribe
Rhel Extras Other
Subscribe
Serverless
Subscribe
Service Mesh
Subscribe
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-04T12:32:14.681Z
Reserved: 2020-06-12T00:00:00.000Z
Link: CVE-2020-14040
No data.
Status : Modified
Published: 2020-06-17T20:15:09.993
Modified: 2024-11-21T05:02:25.223
Link: CVE-2020-14040
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA
Ubuntu USN