First published: Sat Jan 02 2021(Updated: )
A flaw was found in golang.org. In x/text, a "slice bounds out of range" panic occurs in language.ParseAcceptLanguage while processing a BCP 47 tag.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Golang Text | <0.3.5 | |
redhat/servicemesh | <0:2.0.9-3.el8 | 0:2.0.9-3.el8 |
redhat/git-lfs | <0:2.13.3-3.el8_6 | 0:2.13.3-3.el8_6 |
redhat/podman | <2:4.2.0-3.el9 | 2:4.2.0-3.el9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
CVE-2020-28852 is a vulnerability in golang.org/x/text that allows for a "slice bounds out of range" panic.
CVE-2020-28852 has a severity rating of 7.5 (high).
The software affected by CVE-2020-28852 includes golang.org/x/text versions up to and exclusive 0.3.5, servicemesh versions up to and exclusive 0:2.0.9-3.el8, git-lfs versions up to and exclusive 0:2.13.3-3.el8_6, and podman versions up to and exclusive 2:4.2.0-3.el9.
To fix CVE-2020-28852, update the affected software to the recommended version, such as golang.org/x/text version 0.3.5.
You can find more information about CVE-2020-28852 in the references provided: [GitHub Issue](https://github.com/golang/go/issues/42536), [Red Hat Bugzilla](https://bugzilla.redhat.com/show_bug.cgi/show_bug.cgi?id=1913365), [Red Hat Bugzilla](https://bugzilla.redhat.com/show_bug.cgi/show_bug.cgi?id=1913364).