PT-2020-17120 · Dhowden · Dhowden Tag
Jayl1N
·
Published
2020-12-28
·
Updated
2023-02-07
·
CVE-2020-29244
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
dhowden tag versions prior to 0.0.0-20201120070457-d52dcb253c63
dhowden tag versions prior to 2020-11-19
Description
The issue is due to improper bounds checking in several methods, which can trigger a panic via
readAPICFrame, readAtomData, or readTextWithDescrFrame due to attempted out-of-bounds reads. If the package is used to parse user-supplied input, this may be used as a vector for a denial of service attack.Recommendations
For dhowden tag versions prior to 0.0.0-20201120070457-d52dcb253c63, update to version 0.0.0-20201120070457-d52dcb253c63 or later.
For dhowden tag versions prior to 2020-11-19, update to a version released on or after 2020-11-19.
As a temporary workaround, consider restricting the use of methods
readAPICFrame, readAtomData, and readTextWithDescrFrame to minimize the risk of exploitation.Exploit
Fix
Improper Validation of Array Index
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Dhowden Tag