Skip to content

CVE-2023-39533 #16

@RomainLefeuvre

Description

@RomainLefeuvre

Hi,
I hope this message finds you well.

As part of a research experiment, we developed a tool that allows us to crawl through existing vulnerabilities in upstream projects, that are potentially not fixed in fork.
We have a suspicion that https://github.com/gomini/go-mips32 ,which shares commits with https://github.com/golang/go is still vulnerable to CVE-2023-39533

The vulnerability has been fixed upstream via this commit
https://archive.softwareheritage.org/browse/revision/2350afd2e8ab054390e284c95d5b089c142db017/

However, we could not find the patch applied.
If possible, we would like to know whether it is indeed vulnerable to the vulnerability we described.

Your insight would be very valuable for our experiment.
Do not hesitate to contact us if you want more information.
Thanks again.

Romain Lefeuvre and Charly Reux.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions