Total vulnerabilities in the database
The html package (aka x/net/html) through 2018-09-25 in Go mishandles <table><math><select><mi><select></table>, leading to an infinite loop during an html.Parse call because inSelectIM and inSelectInTableIM do not comply with a specification.
Software | From | Fixed in |
---|---|---|
golang / net | - | 2018-09-25.x |
fedoraproject / fedora | 28 | 28.x |
fedoraproject / fedora | 29 | 29.x |
![]() |
- | 0.0.0-20190125091013-d26f9f9a57f3 |