Vulnerability Details CVE-2020-14040
The x/text package before 0.3.3 for Go has a vulnerability in encoding/unicode that could lead to the UTF-16 decoder entering an infinite loop, causing the program to crash or run out of memory. An attacker could provide a single byte to a UTF16 decoder instantiated with UseBOM or ExpectBOM to trigger an infinite loop if the String function on the Decoder is called, or the Decoder is passed to golang.org/x/text/transform.String.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.0
EPSS Ranking 0.3%
CVSS Severity
CVSS v3 Score 7.5
CVSS v2 Score 5.0
Products affected by CVE-2020-14040
-
cpe:2.3:a:golang:text:0.1.0
-
cpe:2.3:a:golang:text:0.2.0
-
cpe:2.3:a:golang:text:0.3.0
-
cpe:2.3:a:golang:text:0.3.1
-
cpe:2.3:a:golang:text:0.3.2
-
cpe:2.3:o:fedoraproject:fedora:32