Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 880669 (CVE-2022-32149) - [Tracker] Go x/text DoS via crafted Accept-Language header
Summary: [Tracker] Go x/text DoS via crafted Accept-Language header
Status: CONFIRMED
Alias: CVE-2022-32149
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal normal (vote)
Assignee: Gentoo Security
URL: https://pkg.go.dev/vuln/GO-2022-1059
Whiteboard:
Keywords:
Depends on: CVE-2022-42968 CVE-2022-39306, CVE-2022-39307
Blocks:
  Show dependency tree
 
Reported: 2022-11-10 00:08 UTC by John Helmert III
Modified: 2022-11-10 00:08 UTC (History)
0 users

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2022-11-10 00:08:34 UTC
CVE-2022-32149:

An attacker may cause a denial of service by crafting an Accept-Language header which ParseAcceptLanguage will take significant time to parse.