On Windows, The IsLocal function does not correctly detect reserved device names in some cases. Reserved names followed by spaces, such as "COM1 ", and reserved names "COM" and "LPT" followed by superscript 1, 2, or 3, are incorrectly reported as local. With fix, IsLocal now correctly reports these names as non-local.
References
Link | Resource |
---|---|
https://go.dev/issue/63713 | Issue Tracking Vendor Advisory |
https://go.dev/cl/540277 | Issue Tracking Vendor Advisory |
https://groups.google.com/g/golang-announce/c/4tU8LZfBFkY | Issue Tracking Mailing List Vendor Advisory |
https://pkg.go.dev/vuln/GO-2023-2186 | Issue Tracking Vendor Advisory |
Configurations
Configuration 1 (hide)
AND |
|
History
17 Nov 2023, 16:39
Type | Values Removed | Values Added |
---|---|---|
CWE | NVD-CWE-noinfo | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 5.3 |
CPE | cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:* cpe:2.3:a:golang:go:*:*:*:*:*:*:*:* |
|
First Time |
Microsoft windows
Golang go Golang Microsoft |
|
References | () https://go.dev/issue/63713 - Issue Tracking, Vendor Advisory | |
References | () https://go.dev/cl/540277 - Issue Tracking, Vendor Advisory | |
References | () https://groups.google.com/g/golang-announce/c/4tU8LZfBFkY - Issue Tracking, Mailing List, Vendor Advisory | |
References | () https://pkg.go.dev/vuln/GO-2023-2186 - Issue Tracking, Vendor Advisory |
09 Nov 2023, 17:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-11-09 17:15
Updated : 2024-09-03 19:35
NVD link : CVE-2023-45284
Mitre link : CVE-2023-45284
JSON object : View
Products Affected
golang
- go
microsoft
- windows
CWE