Unrated severityNVD Advisory· Published Jan 2, 2021· Updated Aug 4, 2024
CVE-2020-28851
CVE-2020-28851
Description
In x/text in Go 1.15.4, an "index out of range" panic occurs in language.ParseAcceptLanguage while parsing the -u- extension. (x/text/language is supposed to be able to parse an HTTP Accept-Language header.)
Affected products
9- Go/x/textdescription
- osv-coords8 versionspkg:bitnami/golangpkg:rpm/almalinux/git-lfspkg:rpm/almalinux/podmanpkg:rpm/almalinux/podman-dockerpkg:rpm/almalinux/podman-gvproxypkg:rpm/almalinux/podman-pluginspkg:rpm/almalinux/podman-remotepkg:rpm/almalinux/podman-tests
>= 1.15.4, < 1.15.5+ 7 more
- (no CPE)range: >= 1.15.4, < 1.15.5
- (no CPE)range: < 2.13.3-3.el8_6
- (no CPE)range: < 2:4.2.0-3.el9
- (no CPE)range: < 2:4.2.0-3.el9
- (no CPE)range: < 2:4.2.0-3.el9
- (no CPE)range: < 2:4.2.0-3.el9
- (no CPE)range: < 2:4.2.0-3.el9
- (no CPE)range: < 2:4.2.0-3.el9
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- github.com/golang/go/issues/42535mitrex_refsource_MISC
- security.netapp.com/advisory/ntap-20210212-0004/mitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.