First published: Sun Sep 16 2018(Updated: )
The html package (aka x/net/html) before 2018-07-13 in Go mishandles "in frameset" insertion mode, leading to a "panic: runtime error" for html.Parse of <template><object>, <template><applet>, or <template><marquee>. This is related to HTMLTreeBuilder.cpp in WebKit.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
go/golang.org/x/net | <0.0.0-20180816102801-aaf60122140d | 0.0.0-20180816102801-aaf60122140d |
golang net | <=2018-07-12 | |
Fedora | =28 | |
Fedora | =29 | |
Fedoraproject Fedora | =28 | |
Fedoraproject Fedora | =29 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.