Loop with Unreachable Exit Condition ('Infinite Loop') Affecting golang-golang-x-net-dev package, versions *


Severity

Recommended
low

Based on Ubuntu security rating.

Threat Intelligence

EPSS
0.25% (66th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-UBUNTU2004-GOLANGGOLANGXNETDEV-579246
  • published28 Oct 2018
  • disclosed1 Oct 2018

Introduced: 1 Oct 2018

CVE-2018-17846  (opens in a new tab)
CWE-835  (opens in a new tab)

How to fix?

There is no fixed version for Ubuntu:20.04 golang-golang-x-net-dev.

NVD Description

Note: Versions mentioned in the description apply only to the upstream golang-golang-x-net-dev package and not the golang-golang-x-net-dev package as distributed by Ubuntu. See How to fix? for Ubuntu:20.04 relevant fixed versions and status.

The html package (aka x/net/html) through 2018-09-25 in Go mishandles <table><math><select><mi><select></table>, leading to an infinite loop during an html.Parse call because inSelectIM and inSelectInTableIM do not comply with a specification.

CVSS Scores

version 3.1