Guido Vranken discovered that Go Networking handled input to the Parse functions inefficiently. An attacker could possibly use this issue to cause denial of service. This update addresses the issue in the golang-golang-x-net and golang-golang-x-net-dev packages, as well as the library vendored within adsys and juju-core.
{
"availability": "No subscription required",
"binaries": [
{
"binary_version": "0.9.2~20.04.2ubuntu0.1",
"binary_name": "adsys"
},
{
"binary_version": "0.9.2~20.04.2ubuntu0.1",
"binary_name": "adsys-windows"
}
]
}"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-7197-1.json"
{
"cves": [
{
"id": "CVE-2024-45338",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
},
{
"type": "Ubuntu",
"score": "medium"
}
]
}
],
"ecosystem": "Ubuntu:20.04:LTS"
}
{
"availability": "No subscription required",
"binaries": [
{
"binary_version": "0.14.3~22.04ubuntu0.1",
"binary_name": "adsys"
},
{
"binary_version": "0.14.3~22.04ubuntu0.1",
"binary_name": "adsys-windows"
}
]
}"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-7197-1.json"
{
"cves": [
{
"id": "CVE-2024-45338",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
},
{
"type": "Ubuntu",
"score": "medium"
}
]
}
],
"ecosystem": "Ubuntu:22.04:LTS"
}
{
"availability": "No subscription required",
"binaries": [
{
"binary_version": "0.14.3~24.04ubuntu0.1",
"binary_name": "adsys"
},
{
"binary_version": "0.14.3~24.04ubuntu0.1",
"binary_name": "adsys-windows"
}
]
}"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-7197-1.json"
{
"cves": [
{
"id": "CVE-2024-45338",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
},
{
"type": "Ubuntu",
"score": "medium"
}
]
}
],
"ecosystem": "Ubuntu:24.04:LTS"
}
{
"availability": "Available with Ubuntu Pro (Infra-only): https://ubuntu.com/pro",
"binaries": [
{
"binary_version": "1:0.0+git20160110.4fd4a9f-1ubuntu0.1~esm1",
"binary_name": "golang-go.net-dev"
},
{
"binary_version": "1:0.0+git20160110.4fd4a9f-1ubuntu0.1~esm1",
"binary_name": "golang-golang-x-net-dev"
}
]
}"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-7197-1.json"
{
"cves": [
{
"id": "CVE-2024-45338",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
},
{
"type": "Ubuntu",
"score": "medium"
}
]
}
],
"ecosystem": "Ubuntu:Pro:16.04:LTS"
}
{
"availability": "Available with Ubuntu Pro (Infra-only): https://ubuntu.com/pro",
"binaries": [
{
"binary_version": "2.3.7-0ubuntu0.16.04.1+esm1",
"binary_name": "juju"
},
{
"binary_version": "2.3.7-0ubuntu0.16.04.1+esm1",
"binary_name": "juju-2.0"
}
]
}"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-7197-1.json"
{
"cves": [
{
"id": "CVE-2024-45338",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
},
{
"type": "Ubuntu",
"score": "medium"
}
]
}
],
"ecosystem": "Ubuntu:Pro:16.04:LTS"
}
{
"availability": "Available with Ubuntu Pro: https://ubuntu.com/pro",
"binaries": [
{
"binary_version": "1:0.0+git20170629.c81e7f2+dfsg-2ubuntu0.1~esm1",
"binary_name": "golang-go.net-dev"
},
{
"binary_version": "1:0.0+git20170629.c81e7f2+dfsg-2ubuntu0.1~esm1",
"binary_name": "golang-golang-x-net-dev"
}
]
}"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-7197-1.json"
{
"cves": [
{
"id": "CVE-2024-45338",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
},
{
"type": "Ubuntu",
"score": "medium"
}
]
}
],
"ecosystem": "Ubuntu:Pro:18.04:LTS"
}
{
"availability": "Available with Ubuntu Pro: https://ubuntu.com/pro",
"binaries": [
{
"binary_version": "1:0.0+git20190811.74dc4d7+dfsg-1ubuntu0.1~esm1",
"binary_name": "golang-go.net-dev"
},
{
"binary_version": "1:0.0+git20190811.74dc4d7+dfsg-1ubuntu0.1~esm1",
"binary_name": "golang-golang-x-net-dev"
}
]
}"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-7197-1.json"
{
"cves": [
{
"id": "CVE-2024-45338",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
},
{
"type": "Ubuntu",
"score": "medium"
}
]
}
],
"ecosystem": "Ubuntu:Pro:20.04:LTS"
}
{
"availability": "Available with Ubuntu Pro: https://ubuntu.com/pro",
"binaries": [
{
"binary_version": "1:0.0+git20211209.491a49a+dfsg-1ubuntu0.1~esm1",
"binary_name": "golang-golang-x-net-dev"
}
]
}"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-7197-1.json"
{
"cves": [
{
"id": "CVE-2024-45338",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
},
{
"type": "Ubuntu",
"score": "medium"
}
]
}
],
"ecosystem": "Ubuntu:Pro:22.04:LTS"
}
{
"availability": "Available with Ubuntu Pro: https://ubuntu.com/pro",
"binaries": [
{
"binary_version": "1:0.21.0+dfsg-1ubuntu0.1~esm1",
"binary_name": "golang-golang-x-net-dev"
}
]
}"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-7197-1.json"
{
"cves": [
{
"id": "CVE-2024-45338",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
},
{
"type": "Ubuntu",
"score": "medium"
}
]
}
],
"ecosystem": "Ubuntu:Pro:24.04:LTS"
}