VDB
BDU%3A2022-03899
BDU%3A2022-03899
PUBLISHED
CVSS 7.800000190734863 HIGH
Уязвимость реализации функции SetString() класса Rat пакета math/big языка программирования Go, позволяющая нарушителю вызвать отказ в обслуживании
Risk Scores
CVSS 2.0
7.800000190734863
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Сообщество свободного программного обеспечения, Novell Inc., Red Hat Inc., The Go Project, АО "НППКТ", АО «Концерн ВНИИНС» | Debian GNU/Linux, openSUSE Tumbleweed, Red Hat Quay, OpenSUSE Leap, Openshift Service Mesh, SUSE Linux Enterprise High Performance Computing, Suse Linux Enterprise Server, SUSE Linux Enterprise Server for SAP Applications, SUSE Manager Proxy, SUSE Manager Server, Suse Linux Enterprise Desktop, Red Hat Openshift Data Foundation, SUSE Enterprise Storage, SUSE Linux Enterprise Module for Development Tools, SUSE Manager Retail Branch Server, Red Hat OpenShift Container Platform, Red Hat Migration Toolkit for Containers, Go, Red Hat OpenStack Platform, SUSE Linux Enterprise Real Time, ОСОН ОСнова Оnyx (запись в едином реестре российских программ №5913), ОС ОН «Стрелец» (запись в едином реестре российских программ №6177) |
Timeline
- Jun 29, 2022 CVE Published
- Nov 21, 2023 CVE Updated
References
- https://groups.google.com/g/golang-announce/c/SUsQn0aSgPQ url
- https://lists.debian.org/debian-lts-announce/2022/04/msg00017.html url
- https://lists.debian.org/debian-lts-announce/2022/04/msg00018.html url
- https://security.netapp.com/advisory/ntap-20220225-0006/ url
- https://nvd.nist.gov/vuln/detail/CVE-2022-23772 url
- https://access.redhat.com/security/cve/CVE-2022-23772 url
- https://www.suse.com/security/cve/CVE-2022-23772.html url
- https://поддержка.нппкт.рф/bin/view/ОСнова/Обновления/2.6/ url
- https://strelets.net/patchi-i-obnovleniya-bezopasnosti#16012023 url
- https://github.com/golang/go/issues/50699 advisory
- https://go.dev/doc/devel/release#go1.17.minor advisory
- https://github.com/golang/go/tags advisory