VulnerabilityModified
CVE-2023-45284
On Windows, The IsLocal function does not correctly detect reserved device names in some cases.
MEDIUM 5.3EPSS 0.90%
Does this matter?
Lower severity and a low EPSS score (0.90%). Track it; it rarely justifies an emergency change on its own.
Description
On Windows, The IsLocal function does not correctly detect reserved device names in some cases. Reserved names followed by spaces, such as "COM1 ", and reserved names "COM" and "LPT" followed by superscript 1, 2, or 3, are incorrectly reported as local. With fix, IsLocal now correctly reports these names as non-local.
- CVSS 3.1
- 5.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
- EPSS
- 0.90% probability · 58th percentile
- CISA KEV
- Not listed
- Affected
- golang/go
- Source
- security@golang.org
References
- https://go.dev/cl/540277Issue Tracking, Vendor Advisory
- https://go.dev/issue/63713Issue Tracking, Vendor Advisory
- https://groups.google.com/g/golang-announce/c/4tU8LZfBFkYIssue Tracking, Mailing List, Vendor Advisory
- https://pkg.go.dev/vuln/GO-2023-2186Issue Tracking, Vendor Advisory
- https://go.dev/cl/540277Issue Tracking, Vendor Advisory
- https://go.dev/issue/63713Issue Tracking, Vendor Advisory
- https://groups.google.com/g/golang-announce/c/4tU8LZfBFkYIssue Tracking, Mailing List, Vendor Advisory
- https://pkg.go.dev/vuln/GO-2023-2186Issue Tracking, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.