go/src
Damien Neil 16e5d24480 net/textproto, mime/multipart: avoid unbounded read in MIME header
mime/multipart.Reader.ReadForm allows specifying the maximum amount
of memory that will be consumed by the form. While this limit is
correctly applied to the parsed form data structure, it was not
being applied to individual header lines in a form.

For example, when presented with a form containing a header line
that never ends, ReadForm will continue to read the line until it
runs out of memory.

Limit the amount of data consumed when reading a header.

Fixes CVE-2023-45290
Fixes #65383

Change-Id: I7f9264d25752009e95f6b2c80e3d76aaf321d658
Reviewed-on: https://team-review.git.corp.google.com/c/golang/go-private/+/2134435
Reviewed-by: Roland Shoemaker <bracewell@google.com>
Reviewed-by: Tatiana Bradley <tatianabradley@google.com>
Reviewed-on: https://go-review.googlesource.com/c/go/+/569341
Reviewed-by: Carlos Amedee <carlos@golang.org>
Reviewed-by: Damien Neil <dneil@google.com>
Auto-Submit: Michael Knyszek <mknyszek@google.com>
LUCI-TryBot-Result: Go LUCI <golang-scoped@luci-project-accounts.iam.gserviceaccount.com>
2024-03-05 18:31:56 +00:00
..
archive archive/tar: check returned error before use hdr 2024-02-27 16:39:23 +00:00
arena
bufio
builtin
bytes bytes: add a colon after Output to make the Example in the document display correctly 2024-03-04 15:54:40 +00:00
cmd cmd/go/internal/modload: make it clear -mod can't be set in some cases 2024-03-04 21:01:23 +00:00
cmp
compress
container
context context: update doc comment to link to context interface 2024-02-17 23:25:55 +00:00
crypto crypto/x509: make sure pub key is non-nil before interface conversion 2024-03-05 18:28:56 +00:00
database/sql database/sql: add error check 2024-02-28 20:21:26 +00:00
debug
embed
encoding encoding/json: make use of reflect.Type.{OverflowInt, OverflowUint} 2024-02-29 18:45:05 +00:00
errors
expvar expvar: avoid conflict with user-defined "GET /" route. 2024-02-26 15:31:33 +00:00
flag
fmt fmt: allow padding and minus flags at the same time 2024-03-04 17:31:55 +00:00
go go/types, types2: consistently use error_ type for sub-errors (cleanup) 2024-02-29 22:06:18 +00:00
hash Revert "hash/maphash: parallel run test" 2024-02-20 21:02:04 +00:00
html html/template: replace bytes.Compare call with bytes.Equal 2024-02-27 16:34:44 +00:00
image
index/suffixarray
internal os: don't normalize volumes to drive letters in os.Readlink 2024-03-04 20:38:54 +00:00
io io/fs: set ErrInvalid for FS.Open from SubFS when it fails ValidPath 2024-02-10 02:10:17 +00:00
iter
log log/slog: correct formatting 2024-02-20 20:44:14 +00:00
maps all: run go fmt 2024-02-28 20:35:05 +00:00
math math/rand, math/rand/v2: rename receiver variables 2024-03-04 17:32:49 +00:00
mime net/textproto, mime/multipart: avoid unbounded read in MIME header 2024-03-05 18:31:56 +00:00
net net/textproto, mime/multipart: avoid unbounded read in MIME header 2024-03-05 18:31:56 +00:00
os os: fix 63703.md release notes 2024-03-05 16:20:15 +00:00
path os: don't normalize volumes to drive letters in os.Readlink 2024-03-04 20:38:54 +00:00
plugin
reflect runtime: use .Pointers() instead of manual checking 2024-03-04 17:34:30 +00:00
regexp regexp: add available godoc link 2024-02-26 20:50:01 +00:00
runtime os: don't normalize volumes to drive letters in os.Readlink 2024-03-04 20:38:54 +00:00
slices slices: simplify rotate code 2024-03-04 20:01:33 +00:00
sort sort: use math/rand/v2 in tests and benchmarks 2024-02-08 22:59:40 +00:00
strconv
strings strings: make use of sizeclasses in (*Builder).Grow 2024-02-19 19:51:15 +00:00
sync all: run go fmt 2024-02-28 20:35:05 +00:00
syscall syscall: call internal/runtime/syscall.Syscall6 in RawSyscall6 2024-03-04 17:26:21 +00:00
testdata
testing testing: fix typo in comment 2024-02-28 20:32:54 +00:00
text text/tabwriter: add recovered panic message to rethrow 2024-02-29 16:46:34 +00:00
time runtime: move per-P timers state into its own struct 2024-02-29 18:51:47 +00:00
unicode
unsafe
vendor all: update golang.org/x/sys and vendor it 2024-02-08 20:35:26 +00:00
Make.dist
README.vendor
all.bash
all.bat
all.rc
bootstrap.bash
buildall.bash
clean.bash
clean.bat
clean.rc
cmp.bash
go.mod all: update golang.org/x/sys and vendor it 2024-02-08 20:35:26 +00:00
go.sum all: update golang.org/x/sys and vendor it 2024-02-08 20:35:26 +00:00
make.bash cmd: remove support for GOROOT_FINAL 2024-02-21 22:16:54 +00:00
make.bat cmd: remove support for GOROOT_FINAL 2024-02-21 22:16:54 +00:00
make.rc cmd: remove support for GOROOT_FINAL 2024-02-21 22:16:54 +00:00
race.bash
race.bat
run.bash
run.bat
run.rc

README.vendor

Vendoring in std and cmd
========================

The Go command maintains copies of external packages needed by the
standard library in the src/vendor and src/cmd/vendor directories.

There are two modules, std and cmd, defined in src/go.mod and
src/cmd/go.mod. When a package outside std or cmd is imported
by a package inside std or cmd, the import path is interpreted
as if it had a "vendor/" prefix. For example, within "crypto/tls",
an import of "golang.org/x/crypto/cryptobyte" resolves to
"vendor/golang.org/x/crypto/cryptobyte". When a package with the
same path is imported from a package outside std or cmd, it will
be resolved normally. Consequently, a binary may be built with two
copies of a package at different versions if the package is
imported normally and vendored by the standard library.

Vendored packages are internally renamed with a "vendor/" prefix
to preserve the invariant that all packages have distinct paths.
This is necessary to avoid compiler and linker conflicts. Adding
a "vendor/" prefix also maintains the invariant that standard
library packages begin with a dotless path element.

The module requirements of std and cmd do not influence version
selection in other modules. They are only considered when running
module commands like 'go get' and 'go mod vendor' from a directory
in GOROOT/src.

Maintaining vendor directories
==============================

Before updating vendor directories, ensure that module mode is enabled.
Make sure that GO111MODULE is not set in the environment, or that it is
set to 'on' or 'auto'.

Requirements may be added, updated, and removed with 'go get'.
The vendor directory may be updated with 'go mod vendor'.
A typical sequence might be:

    cd src
    go get golang.org/x/net@master
    go mod tidy
    go mod vendor

Use caution when passing '-u' to 'go get'. The '-u' flag updates
modules providing all transitively imported packages, not only
the module providing the target package.

Note that 'go mod vendor' only copies packages that are transitively
imported by packages in the current module. If a new package is needed,
it should be imported before running 'go mod vendor'.