Parsing PKIX distinguished names containing the string "=#" can cause excessive memory consumption.
{ "url": "https://pkg.go.dev/vuln/GO-2023-1589", "review_status": "REVIEWED" }
{ "imports": [ { "symbols": [ "ParseDistinguishedName" ], "path": "github.com/notaryproject/notation-go/internal/pkix" }, { "symbols": [ "New", "NewFromConfig", "verifier.Verify", "verifyX509TrustedIdentities" ], "path": "github.com/notaryproject/notation-go/verifier" }, { "symbols": [ "Document.Validate", "validateTrustedIdentities" ], "path": "github.com/notaryproject/notation-go/verifier/trustpolicy" } ] }