Description
The ParseAddressList function incorrectly handles comments (text within parentheses) within display names. Since this is a misalignment with conforming address parsers, it can result in different trust decisions being made by programs using different parsers.
Published: 2024-03-05
Score: 7.5 High
EPSS: 2.0% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2024-22162 The ParseAddressList function incorrectly handles comments (text within parentheses) within display names. Since this is a misalignment with conforming address parsers, it can result in different trust decisions being made by programs using different parsers.
Ubuntu USN Ubuntu USN USN-6886-1 Go vulnerabilities
Ubuntu USN Ubuntu USN USN-7109-1 Go vulnerabilities
Ubuntu USN Ubuntu USN USN-7111-1 Go vulnerabilities
History

Fri, 27 Jun 2025 02:45:00 +0000

Type Values Removed Values Added
First Time appeared Redhat ceph Storage
CPEs cpe:/a:redhat:ceph_storage:8.1::el9
Vendors & Products Redhat ceph Storage

Thu, 13 Feb 2025 18:15:00 +0000

Type Values Removed Values Added
First Time appeared Go Standard Library
Go Standard Library net\/mail
CPEs cpe:2.3:a:go_standard_library:net\/mail:*:*:*:*:*:*:*:*
Vendors & Products Go Standard Library
Go Standard Library net\/mail
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 14 Nov 2024 02:45:00 +0000

Type Values Removed Values Added
First Time appeared Redhat openstack Podified
CPEs cpe:/a:redhat:openstack_podified:1.0::el9
Vendors & Products Redhat openstack Podified

Subscriptions

Go Standard Library Net\/mail
Redhat Advanced Cluster Security Ceph Storage Enterprise Linux Kube Descheduler Operator Openshift Openshift Api Data Protection Openshift Distributed Tracing Openshift Secondary Scheduler Openshift Serverless Openstack Podified Rhmt Run Once Duration Override Operator Serverless
cve-icon MITRE

Status: PUBLISHED

Assigner: Go

Published:

Updated: 2025-02-13T17:40:24.430Z

Reserved: 2024-01-30T16:05:14.757Z

Link: CVE-2024-24784

cve-icon Vulnrichment

Updated: 2024-08-01T23:28:12.523Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-03-05T23:15:07.733

Modified: 2024-11-21T08:59:41.820

Link: CVE-2024-24784

cve-icon Redhat

Severity : Moderate

Publid Date: 2024-03-05T00:00:00Z

Links: CVE-2024-24784 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses