HIGH
Infinite loop in github.com/btcsuite/go-socks
Published Dec 27, 2022
7.5
HIGHCVSS 3.1
EPSS 0.78%
Description
The RemoteAddr and LocalAddr methods on the returned net.Conn may call themselves, leading to an infinite loop which will crash the program due to a stack overflow.
Affected products
-
- Version 0StatusaffectedConstraints<0.0.0-20130808000456-233bccbb1abe
- Version
- Vendor Github.com/btcsuitereleases/go-Socks Product Github.com/btcsuitereleases/go-Socks Defaultunaffected
- Version 0StatusaffectedConstraints<0.0.0-20130808000456-233bccbb1abe
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Github.com/btcsuite/go-Socks | Github.com/btcsuite/go-Socks | unaffected |
| ||||||
| Github.com/btcsuitereleases/go-Socks | Github.com/btcsuitereleases/go-Socks | unaffected |
|
- < 2013-08-07
No data.
No Red Hat product state for this CVE.
github.com/btcsuite/go-socks
Go
Introduced 0 Fixed 0.0.0-20130808000456-233bccbb1abegithub.com/btcsuitereleases/go-socks
Go
Introduced 0 Fixed 0.0.0-20130808000456-233bccbb1abe
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| Go | github.com/btcsuite/go-socks | 0 | 0.0.0-20130808000456-233bccbb1abe |
| Go | github.com/btcsuitereleases/go-socks | 0 | 0.0.0-20130808000456-233bccbb1abe |
Remediation
No remediation recorded yet.
Weaknesses (1)
References (4)
- https://github.com/advisories/GHSA-gxgj-xjcw-fv9p Advisory
- https://github.com/btcsuite/go-socks/commit/233bccbb1abe02f05750f7ace66f5bffdb13defc PatchThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2013-10005
- https://pkg.go.dev/vuln/GO-2020-0024 PatchVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://github.com/advisories/GHSA-gxgj-xjcw-fv9p | Advisory | |
| https://github.com/btcsuite/go-socks/commit/233bccbb1abe02f05750f7ace66f5bffdb13defc | PatchThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2013-10005 | ||
| https://pkg.go.dev/vuln/GO-2020-0024 | PatchVendor Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Go
Published Dec 27, 2022
Updated Apr 11, 2025
Reserved Jul 29, 2022
Link CVE-2013-10005
CISA Vulnrichment
GHSA-GXGJ-XJCW-FV9P Updated Apr 11, 2025