First published: Tue Apr 04 2023(Updated: )
Calling any of the Parse functions on Go source code which contains //line directives with very large line numbers can cause an infinite loop due to integer overflow.
Credit: security@golang.org security@golang.org security@golang.org
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/golang | <1.20.3 | 1.20.3 |
redhat/golang | <1.19.8 | 1.19.8 |
debian/golang-1.15 | <=1.15.15-1~deb11u4 | |
debian/golang-1.19 | 1.19.8-2 | |
Ruby | <1.19.8 | |
Ruby | >=1.20.0<1.20.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-24537
The severity of CVE-2023-24537 is high with a score of 7.5.
CVE-2023-24537 affects the following software packages: golang (version up to 1.19.8) and golang (version up to 1.20.3).
To fix CVE-2023-24537, update your golang package to version 1.19.8 or version 1.20.3 depending on your current version.
Yes, you can find more information about CVE-2023-24537 at the following references: [Link 1](https://go.dev/cl/482078), [Link 2](https://go.dev/issue/59180), [Link 3](https://groups.google.com/g/golang-announce/c/Xdv6JL9ENs8).