CVE Vulnerabilities

CVE-2023-45284

Published: Nov 09, 2023 | Modified: Jun 17, 2026
CVSS 3.x
5.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

On Windows, The IsLocal function does not correctly detect reserved device names in some cases. Reserved names followed by spaces, such as COM1 , and reserved names COM and LPT followed by superscript 1, 2, or 3, are incorrectly reported as local. With fix, IsLocal now correctly reports these names as non-local.

Affected Software

NameVendorStart VersionEnd Version
GoGolang*1.20.11 (excluding)
GoGolang1.21.0-0 (including)1.21.4 (excluding)
GolangUbuntutrusty*
GolangUbuntuxenial*
Golang-1.10Ubuntubionic*
Golang-1.10Ubuntuesm-infra/xenial*
Golang-1.10Ubuntutrusty*
Golang-1.10Ubuntutrusty/esm*
Golang-1.10Ubuntuxenial*
Golang-1.13Ubuntubionic*
Golang-1.13Ubuntuesm-apps/xenial*
Golang-1.13Ubuntufocal*
Golang-1.13Ubuntuxenial*
Golang-1.14Ubuntufocal*
Golang-1.16Ubuntubionic*
Golang-1.16Ubuntufocal*
Golang-1.18Ubuntubionic*
Golang-1.18Ubuntuesm-apps/xenial*
Golang-1.18Ubuntufocal*
Golang-1.19Ubuntulunar*
Golang-1.6Ubuntuesm-infra/xenial*
Golang-1.6Ubuntutrusty*
Golang-1.6Ubuntuxenial*
Golang-1.8Ubuntubionic*
Golang-1.9Ubuntubionic*

References