Rapid7 Vulnerability & Exploit Database

Oracle Linux: CVE-2020-14040: ELSA-2020-4694: container-tools:ol8 security, bug fix, and enhancement update (MODERATE) (Multiple Advisories)

Free InsightVM Trial No Credit Card Necessary
2024 Attack Intel Report Latest research by Rapid7 Labs
Back to Search

Oracle Linux: CVE-2020-14040: ELSA-2020-4694: container-tools:ol8 security, bug fix, and enhancement update (MODERATE) (Multiple Advisories)

Severity
8
CVSS
(AV:N/AC:L/Au:N/C:N/I:N/A:C)
Published
06/17/2020
Created
09/15/2020
Added
09/12/2020
Modified
12/06/2024

Description

The x/text package before 0.3.3 for Go has a vulnerability in encoding/unicode that could lead to the UTF-16 decoder entering an infinite loop, causing the program to crash or run out of memory. An attacker could provide a single byte to a UTF16 decoder instantiated with UseBOM or ExpectBOM to trigger an infinite loop if the String function on the Decoder is called, or the Decoder is passed to golang.org/x/text/transform.String. A denial of service vulnerability was found in the golang.org/x/text library. A library or application must use one of the vulnerable functions, such as unicode.Transform, transform.String, or transform.Byte, to be susceptible to this vulnerability. If an attacker is able to supply specific characters or strings to the vulnerable application, there is the potential to cause an infinite loop to occur using more memory, resulting in a denial of service.

Solution(s)

  • oracle-linux-upgrade-buildah
  • oracle-linux-upgrade-buildah-tests
  • oracle-linux-upgrade-cockpit-podman
  • oracle-linux-upgrade-conmon
  • oracle-linux-upgrade-containernetworking-plugins
  • oracle-linux-upgrade-containers-common
  • oracle-linux-upgrade-container-selinux
  • oracle-linux-upgrade-crit
  • oracle-linux-upgrade-criu
  • oracle-linux-upgrade-crun
  • oracle-linux-upgrade-delve
  • oracle-linux-upgrade-fuse-overlayfs
  • oracle-linux-upgrade-golang
  • oracle-linux-upgrade-golang-bin
  • oracle-linux-upgrade-golang-docs
  • oracle-linux-upgrade-golang-misc
  • oracle-linux-upgrade-golang-race
  • oracle-linux-upgrade-golang-src
  • oracle-linux-upgrade-golang-tests
  • oracle-linux-upgrade-go-toolset
  • oracle-linux-upgrade-libslirp
  • oracle-linux-upgrade-libslirp-devel
  • oracle-linux-upgrade-oci-seccomp-bpf-hook
  • oracle-linux-upgrade-podman
  • oracle-linux-upgrade-podman-catatonit
  • oracle-linux-upgrade-podman-docker
  • oracle-linux-upgrade-podman-remote
  • oracle-linux-upgrade-podman-tests
  • oracle-linux-upgrade-python3-criu
  • oracle-linux-upgrade-python-podman-api
  • oracle-linux-upgrade-runc
  • oracle-linux-upgrade-skopeo
  • oracle-linux-upgrade-skopeo-tests
  • oracle-linux-upgrade-slirp4netns
  • oracle-linux-upgrade-udica

insightVM

Advanced vulnerability management analytics and reporting.
Key Features
  • Lightweight Endpoint Agent
  • Live Dashboards
  • Real Risk Prioritization
  • IT-Integrated Remediation Projects
  • Cloud, Virtual, and Container Assessment
  • Integrated Threat Feeds
  • Easy-to-Use RESTful API
  • Automation-Assisted Patching
  • Automated Containment
Free InsightVM Trial View All Features

With Rapid7 live dashboards, I have a clear view of all the assets on my network, which ones can be exploited, and what I need to do in order to reduce the risk in my environment in real-time. No other tool gives us that kind of value and insight.

– Scott Cheney, Manager of Information Security, Sierra View Medical Center

;