Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2022-30629

Опубликовано: 10 авг. 2022
Источник: debian
EPSS Низкий

Описание

Non-random values for ticket_age_add in session tickets in crypto/tls before Go 1.17.11 and Go 1.18.3 allow an attacker that can observe TLS handshakes to correlate successive connections by comparing ticket ages during session resumption.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
golang-1.18fixed1.18.3-1package
golang-1.17fixed1.17.11-1package
golang-1.15removedpackage
golang-1.15no-dsabullseyepackage
golang-1.11removedpackage
golang-1.11postponedbusterpackage
golang-1.8removedpackage
golang-1.8not-affectedstretchpackage
golang-1.7removedpackage
golang-1.7not-affectedstretchpackage

Примечания

  • https://groups.google.com/g/golang-announce/c/TzIC9-t8Ytg

  • https://go.dev/issue/52814

  • https://github.com/golang/go/commit/c838098c327a1b6d63446f4722e943b02d235d78 (go1.18.3)

  • https://github.com/golang/go/commit/c15a8e2dbb5ac376a6ed890735341b812d6b965c (go1.17.11)

EPSS

Процентиль: 15%
0.00048
Низкий

Связанные уязвимости

CVSS3: 3.1
ubuntu
почти 3 года назад

Non-random values for ticket_age_add in session tickets in crypto/tls before Go 1.17.11 and Go 1.18.3 allow an attacker that can observe TLS handshakes to correlate successive connections by comparing ticket ages during session resumption.

CVSS3: 3.1
redhat
около 3 лет назад

Non-random values for ticket_age_add in session tickets in crypto/tls before Go 1.17.11 and Go 1.18.3 allow an attacker that can observe TLS handshakes to correlate successive connections by comparing ticket ages during session resumption.

CVSS3: 3.1
nvd
почти 3 года назад

Non-random values for ticket_age_add in session tickets in crypto/tls before Go 1.17.11 and Go 1.18.3 allow an attacker that can observe TLS handshakes to correlate successive connections by comparing ticket ages during session resumption.

CVSS3: 3.1
msrc
почти 3 года назад

Описание отсутствует

CVSS3: 7.5
github
почти 3 года назад

Non-random values for ticket_age_add in session tickets in crypto/tls before Go 1.17.11 and Go 1.18.3 allow an attacker that can observe TLS handshakes to correlate successive connections by comparing ticket ages during session resumption.

EPSS

Процентиль: 15%
0.00048
Низкий