Source |
Bleeping Computer |
Identifiant |
3190792 |
Date de publication |
2021-08-07 04:25:00 (vue: 2021-08-07 17:05:34) |
Titre |
Go, Rust "net" library affected by critical IP address validation vulnerability |
Texte |
The commonly used "net" library in Go and Rust languages is also impacted by the mixed-format IP address validation vulnerability. The bug has to do with how "net" treats IP addresses as decimal, even when they are provided in a mixed (octal-decimal) format, and therefore making applications vulnerable to SSRF and RFI. [...] |
Notes |
|
Envoyé |
Oui |
Condensat |
address addresses affected also applications are bug commonly critical decimal even format has how impacted languages library mixed net octal provided rfi rust ssrf therefore making treats used validation vulnerability vulnerable when and library |
Tags |
Vulnerability
|
Stories |
|
Move |
|