GO-2020-0005
Dashboard / Vulnerabilities / GO-2020-0005
Summary: Panic due to malformed WALs in go.etcd.io/etcd
Details: Malformed WALs can be constructed such that WAL.ReadAll can cause attempted out of bounds reads, or creation of arbitrarily sized slices, which may be used as a DoS vector.
References: https://github.com/etcd-io/etcd/pull/11793, https://github.com/etcd-io/etcd/commit/f4b650b51dc4a53a8700700dc12e1242ac56ba07, https://github.com/etcd-io/etcd/blob/master/security/SECURITY_AUDIT.pdf
Affected packages
Package
Name: go.etcd.io/etcd
Purl: pkg:golang/go.etcd.io/etcd
Affected ranges
Type: SEMVER
Events:
Introduced- 0
Fixed -0.5.0-alpha.5.0.20200423152442-f4b650b51dc4
Affected versions
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
