Improper Validation of Array Index in Go Text - CVE-2020-28851,CVE-2020-28852

 

Improper Validation of Array Index in Go Text - CVE-2020-28851,CVE-2020-28852

Published: October 26, 2022


Vulnerability identifier: #VU68779
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-28851,CVE-2020-28852
CWE-ID: CWE-129
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to improper validation of array index in language.ParseAcceptLanguage while processing a BCP 47 tag. A remote attacker can send a specially crafted HTTP request containing a malformed HTTP Accept-Language header and perform a denial of service (DoS) attack.


Affected software

Go Text
Oracle Linux
Fedora
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Anolis OS
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Ubuntu
Migration Toolkit for Containers
IBM Cloud Pak System
Splunk Enterprise
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
golang-golang-x-text-dev (Ubuntu package)
golang-x-text-dev (Ubuntu package)
golang
git-lfs (Red Hat package)
git-lfs
podman (Red Hat package)
Cloud Pak for Security (CP4S)
Red Hat Advanced Cluster Management for Kubernetes
IBM Fusion HCI
IBM Watson Machine Learning Accelerator
IBM CICS TX Standard
IBM CICS TX Advanced

How to mitigate CVE-2020-28851,CVE-2020-28852

Install updates from vendor's website.

Go Text - update to 0.3.6
Migration Toolkit for Containers - update to 1.7.6
Splunk Enterprise - addressed in versions 8.2.12, 9.0.6, 9.1.1
golang-golang-x-text-dev (Ubuntu package) - addressed in versions 0.0~git20170627.0.6353ef0-1ubuntu2.1, 0.3.2-4ubuntu0.1, 0.3.7-1ubuntu0.20.04.1, 0.3.7-1ubuntu0.22.10.1
golang-x-text-dev (Ubuntu package) - update to 0.0~git20170627.0.6353ef0-1ubuntu2.1
Cloud Pak for Security (CP4S) - update to 1.10.10.0
golang - update to 1.15.14-1.el7
Red Hat Advanced Cluster Management for Kubernetes - update to 2.2.2
IBM Watson Machine Learning Accelerator - update to 2.3.9
IBM Fusion HCI - update to 2.7.0
git-lfs (Red Hat package) - update to 2.13.3-3.el8_6
git-lfs - update to 2.13.3-3.0.1
podman (Red Hat package) - update to 4.2.0-3.el9
IBM CICS TX Standard - update to 11.1.0.0 ifix5
IBM CICS TX Advanced - update to 11.1.0.0 ifix5

External References

Related Security Bulletins