Improper Validation of Array Index in Go Text - CVE-2020-28851,CVE-2020-28852
Published: October 26, 2022
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to improper validation of array index in language.ParseAcceptLanguage while processing a BCP 47 tag. A remote attacker can send a specially crafted HTTP request containing a malformed HTTP Accept-Language header and perform a denial of service (DoS) attack.
Affected software
Oracle Linux
Fedora
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Anolis OS
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Ubuntu
Migration Toolkit for Containers
IBM Cloud Pak System
Splunk Enterprise
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
golang-golang-x-text-dev (Ubuntu package)
golang-x-text-dev (Ubuntu package)
golang
git-lfs (Red Hat package)
git-lfs
podman (Red Hat package)
Cloud Pak for Security (CP4S)
Red Hat Advanced Cluster Management for Kubernetes
IBM Fusion HCI
IBM Watson Machine Learning Accelerator
IBM CICS TX Standard
IBM CICS TX Advanced
How to mitigate CVE-2020-28851,CVE-2020-28852
Migration Toolkit for Containers - update to 1.7.6
Splunk Enterprise - addressed in versions 8.2.12, 9.0.6, 9.1.1
golang-golang-x-text-dev (Ubuntu package) - addressed in versions 0.0~git20170627.0.6353ef0-1ubuntu2.1, 0.3.2-4ubuntu0.1, 0.3.7-1ubuntu0.20.04.1, 0.3.7-1ubuntu0.22.10.1
golang-x-text-dev (Ubuntu package) - update to 0.0~git20170627.0.6353ef0-1ubuntu2.1
Cloud Pak for Security (CP4S) - update to 1.10.10.0
golang - update to 1.15.14-1.el7
Red Hat Advanced Cluster Management for Kubernetes - update to 2.2.2
IBM Watson Machine Learning Accelerator - update to 2.3.9
IBM Fusion HCI - update to 2.7.0
git-lfs (Red Hat package) - update to 2.13.3-3.el8_6
git-lfs - update to 2.13.3-3.0.1
podman (Red Hat package) - update to 4.2.0-3.el9
IBM CICS TX Standard - update to 11.1.0.0 ifix5
IBM CICS TX Advanced - update to 11.1.0.0 ifix5
External References
Related Security Bulletins
- Denial of service in Go Text
- Red Hat Enterprise Linux 8 update for git-lfs
- Red Hat Enterprise Linux 9 update for podman
- Multiple vulnerabilities in Migration Toolkit for Containers (MTC)
- Ubuntu update for golang-golang-x-text
- Improper validation of array index in IBM CICS TX Advanced
- Improper validation of array index in IBM CICS TX Standard
- Multiple vulnerabilities in IBM Cloud Pak for Security (CP4S)
- Multiple vulnerabilities in Oracle Linux
- Splunk Enterprise update for third-party packages
- Multiple vulnerabilities in IBM Storage Fusion
- Multiple vulnerabilities in IBM Watson Machine Learning Accelerator on Cloud Pak for Data
- Fedora EPEL 7 update for golang
- Anolis OS update for git-lfs
- Multiple vulnerabilities in IBM Cloud Pak System
- Multiple vulnerabilities in Red Hat Advanced Cluster Management for Kubernetes 2.2