Unrated severityNVD Advisory· Published Jan 2, 2021· Updated Aug 4, 2024
CVE-2020-28852
CVE-2020-28852
Description
In x/text in Go before v0.3.5, a "slice bounds out of range" panic occurs in language.ParseAcceptLanguage while processing a BCP 47 tag. (x/text/language is supposed to be able to parse an HTTP Accept-Language header.)
Affected products
8- Go/x/textdescription
- osv-coords7 versionspkg:rpm/almalinux/git-lfspkg:rpm/almalinux/podmanpkg:rpm/almalinux/podman-dockerpkg:rpm/almalinux/podman-gvproxypkg:rpm/almalinux/podman-pluginspkg:rpm/almalinux/podman-remotepkg:rpm/almalinux/podman-tests
< 2.13.3-3.el8_6+ 6 more
- (no CPE)range: < 2.13.3-3.el8_6
- (no CPE)range: < 2:4.2.0-3.el9
- (no CPE)range: < 2:4.2.0-3.el9
- (no CPE)range: < 2:4.2.0-3.el9
- (no CPE)range: < 2:4.2.0-3.el9
- (no CPE)range: < 2:4.2.0-3.el9
- (no CPE)range: < 2:4.2.0-3.el9
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- github.com/golang/go/issues/42536mitrex_refsource_MISC
- security.netapp.com/advisory/ntap-20210212-0004/mitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.