CVE-2018-17847: Buffer Overflow

Published Oct 1, 2018
·
Updated

The html package (aka x/net/html) through 2018-09-25 in Go mishandles <svg><template><desc><t><svg></template>, leading to a panic: runtime error (index out of range) in (nodeStack).pop in node.go, called from (parser).clearActiveFormattingElements, during an html.Parse call.

Other sources

The html package (aka x/net/html) through 2018-09-25 in Go mishandles <svg><template><desc><t><svg></template>, leading to a "panic: runtime error" (index out of range) in (nodeStack).pop in node.go, called from (parser).clearActiveFormattingElements, during an html.Parse call.

Affected Software

4 affected componentsFixes available
go/golang.org/x/net<0.0.0-20190125002852-4b62a64f59f7
0.0.0-20190125002852-4b62a64f59f7
Golang Net<=2018-09-25
Fedoraproject Fedora=28
Fedoraproject Fedora=29

Event History

Oct 1, 2018
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
May 13, 2022
Advisory Published
via GitHub·01:19 AM

Frequently Asked Questions

1

What is the severity of CVE-2018-17847?

CVE-2018-17847 has a medium severity due to its ability to cause a panic in the Go HTML parser.

2

How do I fix CVE-2018-17847?

To fix CVE-2018-17847, update the x/net/html package to version 0.0.0-20190125002852-4b62a64f59f7 or later.

3

What versions of Go are affected by CVE-2018-17847?

CVE-2018-17847 affects versions of the Go x/net/html package prior to the fix released on 2019-01-25.

4

What impact does CVE-2018-17847 have on applications?

Applications using the affected versions of the Go html package may crash if they encounter specific SVG elements during parsing.

5

Is CVE-2018-17847 specifically tied to any operating systems?

CVE-2018-17847 primarily affects the Go programming environment and may also impact applications running on Fedora 28 and 29.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203