Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2021-34558

Опубликовано: 15 июл. 2021
Источник: debian
EPSS Низкий

Описание

The crypto/tls package of Go through 1.16.5 does not properly assert that the type of public key in an X.509 certificate matches the expected type when doing a RSA based key exchange, allowing a malicious TLS server to cause a TLS client to panic.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
golang-1.16fixed1.16.6-1package
golang-1.15fixed1.15.9-6package
golang-1.11removedpackage
golang-1.11postponedbusterpackage
golang-1.8removedpackage
golang-1.8postponedstretchpackage
golang-1.7removedpackage
golang-1.7postponedstretchpackage

Примечания

  • https://github.com/golang/go/issues/47143

  • https://github.com/golang/go/commit/58bc454a11d4b3dbc03f44dfcabb9068a9c076f4 (1.16.x)

  • key_agreement.go also bundled in various other packages

EPSS

Процентиль: 74%
0.00839
Низкий

Связанные уязвимости

CVSS3: 6.5
ubuntu
почти 4 года назад

The crypto/tls package of Go through 1.16.5 does not properly assert that the type of public key in an X.509 certificate matches the expected type when doing a RSA based key exchange, allowing a malicious TLS server to cause a TLS client to panic.

CVSS3: 6.5
redhat
почти 4 года назад

The crypto/tls package of Go through 1.16.5 does not properly assert that the type of public key in an X.509 certificate matches the expected type when doing a RSA based key exchange, allowing a malicious TLS server to cause a TLS client to panic.

CVSS3: 6.5
nvd
почти 4 года назад

The crypto/tls package of Go through 1.16.5 does not properly assert that the type of public key in an X.509 certificate matches the expected type when doing a RSA based key exchange, allowing a malicious TLS server to cause a TLS client to panic.

CVSS3: 6.5
msrc
почти 4 года назад

Описание отсутствует

suse-cvrf
почти 4 года назад

Security update for go1.15

EPSS

Процентиль: 74%
0.00839
Низкий