漏洞信息详情
Zhangfannie go 安全漏洞
漏洞简介
Zhangfannie go是 Zhangfannie开源的一个应用软件。提供一种开放源代码编程语言,可轻松构建简单,可靠和高效的软件。
Go before 1.15.9 and 1.16.x before 1.16.1 存在安全漏洞,该漏洞源于TokenReader返回元素中间的EOF,会有一个无限循环。
漏洞公告
目前厂商已发布升级补丁以修复漏洞,补丁获取链接:
https://groups.google.com/g/golang-announce/c/MfiLYjG-RAw
参考网址
来源:MISC
链接:https://groups.google.com/g/golang-announce/c/MfiLYjG-RAw
来源:nvd.nist.gov
链接:https://nvd.nist.gov/vuln/detail/CVE-2021-27918
来源:www.ibm.com
链接:https://www.ibm.com/support/pages/node/6486345
来源:www.ibm.com
链接:https://www.ibm.com/blogs/psirt/security-bulletin-operations-dashboard-is-vulnerable-to-go-vulnerabilities-cve-2021-27918-and-cve-2021-27919/
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/164192/Red-Hat-Security-Advisory-2021-3556-01.html
来源:vigilance.fr
链接:https://vigilance.fr/vulnerability/Go-overload-via-NewTokenDecoder-34932
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/163493/Red-Hat-Security-Advisory-2021-2704-01.html
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.2720
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/164178/Red-Hat-Security-Advisory-2021-3555-01.html
来源:www.cybersecurity-help.cz
链接:https://www.cybersecurity-help.cz/vdb/SB2021071516
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/163784/Red-Hat-Security-Advisory-2021-3076-01.html
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.2365
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.3141
来源:www.cybersecurity-help.cz
链接:https://www.cybersecurity-help.cz/vdb/SB2021081122
受影响实体
暂无
补丁
- Zhangfannie go 安全漏洞的修复措施<!--2021-3-10-->
还没有评论,来说两句吧...