CVE Database
/

CVE-2018-17848

Back to search

CVE-2018-17848

Published: Oct 1, 2018

Modified: Aug 5, 2024

PUBLISHED

Description

The html package (aka x/net/html) through 2018-09-25 in Go mishandles <math><template><mn><b></template>, leading to a "panic: runtime error" (index out of range) in (*insertionModeStack).pop in node.go, called from inHeadIM, during an html.Parse call.

VendorProductVersions

n/a

n/a

affected
n/a

References

FEDORA-2019-07d447a1d3
vendor-advisory
x_refsource_FEDORA
FEDORA-2019-07e8e806e0
vendor-advisory
x_refsource_FEDORA

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now