PT-2020-17120 · Dhowden · Dhowden Tag

·

CVE-2020-29244

·

Published

2020-12-28

·

Updated

2023-02-07

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions dhowden tag versions prior to 0.0.0-20201120070457-d52dcb253c63 dhowden tag versions prior to 2020-11-19
Description The issue is due to improper bounds checking in several methods, which can trigger a panic via readAPICFrame, readAtomData, or readTextWithDescrFrame due to attempted out-of-bounds reads. If the package is used to parse user-supplied input, this may be used as a vector for a denial of service attack.
Recommendations For dhowden tag versions prior to 0.0.0-20201120070457-d52dcb253c63, update to version 0.0.0-20201120070457-d52dcb253c63 or later. For dhowden tag versions prior to 2020-11-19, update to a version released on or after 2020-11-19. As a temporary workaround, consider restricting the use of methods readAPICFrame, readAtomData, and readTextWithDescrFrame to minimize the risk of exploitation.

Exploit

Fix

Improper Validation of Array Index

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-29244
GHSA-27MH-3343-6HG5
GHSA-9WM7-RC47-G56M
GHSA-9XM8-8QVC-VW3P
GHSA-WG79-2CGP-QRJM
GO-2021-0097

Affected Products

Dhowden Tag