Go before 1.13.15 and 14.x before 1.14.7 can have an infinite read loop in ReadUvarint and ReadVarint in encoding/binary via invalid inputs.
References
Link Resource
http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00021.html Mailing List Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00028.html Mailing List Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00029.html Mailing List Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00030.html Mailing List Third Party Advisory
https://groups.google.com/forum/#%21topic/golang-announce/NyPIaucMgXo
https://groups.google.com/forum/#%21topic/golang-announce/_ulYYcIWg3Q
https://lists.debian.org/debian-lts-announce/2020/11/msg00037.html Mailing List Third Party Advisory
https://lists.debian.org/debian-lts-announce/2020/11/msg00038.html Mailing List Third Party Advisory
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6RCFJTMKHY5ICGEM5BUFUEDDGSPJ25XU/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KWRBAH4UZJO3RROQ72SYCUPFCJFA22FO/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TACQFZDPA7AUR6TRZBCX2RGRFSDYLI7O/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WV2VWKFTH4EJGZBZALVUJQJOAQB5MDQ4/
https://security.netapp.com/advisory/ntap-20200924-0002/ Third Party Advisory
https://www.debian.org/security/2021/dsa-4848 Third Party Advisory
https://www.oracle.com/security-alerts/cpuApr2021.html Third Party Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2020-08-06T17:03:33

Updated: 2021-06-14T17:20:17

Reserved: 2020-08-04T00:00:00


Link: CVE-2020-16845

JSON object: View

cve-icon NVD Information

Status : Modified

Published: 2020-08-06T18:15:13.700

Modified: 2023-11-07T03:19:07.360


Link: CVE-2020-16845

JSON object: View

cve-icon Redhat Information

No data.

CWE