FlawAtlas
Search the atlas
CVE-2023-45284 Moderate

Incorrect detection of reserved device names on Windows in path/filepath

On Windows, The IsLocal function does not correctly detect reserved device names in some cases. Reserved names followed by spaces, such as "COM1 ", and reserved names "COM" and "LPT" followed by superscript 1, 2, or 3, are incorrectly reported as local. With fix, IsLocal now correctly reports these names as non-local.

Exploit probability 0.9%
Published November 9, 2023
Required by Not available
Last source change August 12, 2026

02 / AFFECTED SOFTWARE

Affected packages

Unknown Unknown

158 explicit affected versions

Go stdlib
Bitnami golang
Chainguard cluster-autoscaler-1.27
Chainguard cluster-autoscaler-1.27-compat
Wolfi cluster-autoscaler-1.27
Wolfi cluster-autoscaler-1.27-compat
Chainguard cluster-autoscaler-1.26
Chainguard cluster-autoscaler-1.26-compat
Wolfi cluster-autoscaler-1.26
Wolfi cluster-autoscaler-1.26-compat
Chainguard cluster-autoscaler-1.28
Chainguard cluster-autoscaler-1.28-compat
Wolfi cluster-autoscaler-1.28
Wolfi cluster-autoscaler-1.28-compat

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities CVE-2023-45284

On Windows, The IsLocal function does not correctly detect reserved device names in some cases. Reserved names followed by spaces, such as "COM1 ", and reserved names "COM" and "LPT" followed by superscript 1, 2, or 3, are incorrectly reported as local. With fix, IsLocal now correctly reports these names as non-local.

View original source
Open Source Vulnerabilities GO-2023-2186

On Windows, The IsLocal function does not correctly detect reserved device names in some cases. Reserved names followed by spaces, such as "COM1 ", and reserved names "COM" and "LPT" followed by superscript 1, 2, or 3, are incorrectly reported as local. With fix, IsLocal now correctly reports these names as non-local.

View original source
Open Source Vulnerabilities BIT-golang-2023-45284

On Windows, The IsLocal function does not correctly detect reserved device names in some cases. Reserved names followed by spaces, such as "COM1 ", and reserved names "COM" and "LPT" followed by superscript 1, 2, or 3, are incorrectly reported as local. With fix, IsLocal now correctly reports these names as non-local.

View original source

05 / REFERENCES

Further evidence