CVE-2020-16845
06.08.2020, 18:15
Go before 1.13.15 and 14.x before 1.14.7 can have an infinite read loop in ReadUvarint and ReadVarint in encoding/binary via invalid inputs.
Vendor | Product | Version |
---|---|---|
golang | go | 𝑥 < 1.13.15 |
golang | go | 1.14 ≤ 𝑥 < 1.14.7 |
opensuse | leap | 15.1 |
opensuse | leap | 15.2 |
debian | debian_linux | 9.0 |
debian | debian_linux | 10.0 |
𝑥
= Vulnerable software versions

Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
golang |
| ||||||||||||||||||||||||
golang-1.10 |
| ||||||||||||||||||||||||
golang-1.13 |
| ||||||||||||||||||||||||
golang-1.14 |
| ||||||||||||||||||||||||
golang-1.15 |
| ||||||||||||||||||||||||
golang-1.6 |
| ||||||||||||||||||||||||
golang-1.8 |
| ||||||||||||||||||||||||
golang-1.9 |
|
Common Weakness Enumeration
References