CVE-2024-45338

Source
https://nvd.nist.gov/vuln/detail/CVE-2024-45338
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-45338.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2024-45338
Aliases
Related
Published
2024-12-18T21:15:08Z
Modified
2025-01-08T09:55:07.198957Z
Summary
[none]
Details

An attacker can craft an input to the Parse functions that would be processed non-linearly with respect to its length, resulting in extremely slow parsing. This could cause a denial of service.

References

Affected packages

Debian:11 / golang-golang-x-net

Package

Name
golang-golang-x-net
Purl
pkg:deb/debian/golang-golang-x-net?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1:0.*

1:0.0+git20210119.5f4716e+dfsg-4
1:0.0+git20210805.aaa1db6+dfsg-1
1:0.0+git20211209.491a49a+dfsg-1~bpo11+1
1:0.0+git20211209.491a49a+dfsg-1
1:0.0+git20220225.27dd868+dfsg-1
1:0.0+git20220531.c960675+dfsg-1
1:0.0+git20220624.1bab6f3+dfsg-1
1:0.0+git20220728.c7608f3+dfsg-1
1:0.0+git20220728.c7608f3+dfsg-2~bpo11+1
1:0.0+git20220728.c7608f3+dfsg-2
1:0.0+git20221012.0b7e1fb+dfsg-1~bpo11+1
1:0.0+git20221012.0b7e1fb+dfsg-1
1:0.1.0+dfsg-1
1:0.4.0+dfsg-1
1:0.7.0+dfsg-1
1:0.10.0-1
1:0.11.0-1
1:0.14.0-1
1:0.15.0-1
1:0.15.0-2
1:0.17.0+dfsg-1
1:0.19.0+dfsg-1
1:0.20.0+dfsg-1
1:0.21.0+dfsg-1
1:0.22.0+dfsg-1
1:0.23.0+dfsg-1
1:0.24.0+dfsg-1
1:0.25.0+dfsg-1
1:0.26.0+dfsg-1
1:0.26.0+dfsg-2
1:0.27.0-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:12 / golang-golang-x-net

Package

Name
golang-golang-x-net
Purl
pkg:deb/debian/golang-golang-x-net?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1:0.*

1:0.7.0+dfsg-1
1:0.10.0-1
1:0.11.0-1
1:0.14.0-1
1:0.15.0-1
1:0.15.0-2
1:0.17.0+dfsg-1
1:0.19.0+dfsg-1
1:0.20.0+dfsg-1
1:0.21.0+dfsg-1
1:0.22.0+dfsg-1
1:0.23.0+dfsg-1
1:0.24.0+dfsg-1
1:0.25.0+dfsg-1
1:0.26.0+dfsg-1
1:0.26.0+dfsg-2
1:0.27.0-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:13 / golang-golang-x-net

Package

Name
golang-golang-x-net
Purl
pkg:deb/debian/golang-golang-x-net?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1:0.*

1:0.7.0+dfsg-1
1:0.10.0-1
1:0.11.0-1
1:0.14.0-1
1:0.15.0-1
1:0.15.0-2
1:0.17.0+dfsg-1
1:0.19.0+dfsg-1
1:0.20.0+dfsg-1
1:0.21.0+dfsg-1
1:0.22.0+dfsg-1
1:0.23.0+dfsg-1
1:0.24.0+dfsg-1
1:0.25.0+dfsg-1
1:0.26.0+dfsg-1
1:0.26.0+dfsg-2
1:0.27.0-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}