SB2018091607 - Input validation error in Fedoraproject Fedora
Published: September 16, 2018 Updated: August 8, 2020
Security Bulletin ID
SB2018091607
Severity
Medium
Patch available
YES
Number of vulnerabilities
1
Exploitation vector
Remote access
Highest impact
Denial of service
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Input validation error (CVE-ID: CVE-2018-17075)
The vulnerability allows a remote non-authenticated attacker to perform a denial of service (DoS) attack.
The html package (aka x/net/html) before 2018-07-13 in Go mishandles "in frameset" insertion mode, leading to a "panic: runtime error" for html.Parse of <template><object>, <template><applet>, or <template><marquee>. This is related to HTMLTreeBuilder.cpp in WebKit.
Remediation
Install update from vendor's website.
References
- https://bugs.chromium.org/p/chromium/issues/detail?id=829668
- https://github.com/golang/go/issues/27016
- https://github.com/golang/net/commit/aaf60122140d3fcf75376d319f0554393160eb50
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LREEWY6KNLHRWFZ7OT4HVLMVVCGGUHON/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/UKRCI7WIOCOCD3H7NXWRGIRABTQOZOBK/