Описание
SSH clients receiving SSH_AGENT_SUCCESS when expecting a typed response will panic and cause early termination of the client process.
Пакеты
| Пакет | Статус | Версия исправления | Релиз | Тип |
|---|---|---|---|---|
| golang-go.crypto | fixed | 1:0.42.0-1 | package | |
| golang-go.crypto | postponed | bullseye | package |
Примечания
https://github.com/advisories/GHSA-hcg3-q754-cr77
Fixed by: https://github.com/golang/crypto/commit/7292932d45d55c7199324ab0027cc86e8198aa22 (v0.35.0)
EPSS
Процентиль: 9%
0.00032
Низкий
Связанные уязвимости
CVSS3: 7.5
ubuntu
2 месяца назад
SSH clients receiving SSH_AGENT_SUCCESS when expecting a typed response will panic and cause early termination of the client process.
CVSS3: 7.5
nvd
2 месяца назад
SSH clients receiving SSH_AGENT_SUCCESS when expecting a typed response will panic and cause early termination of the client process.
CVSS3: 7.5
msrc
2 месяца назад
Potential denial of service in golang.org/x/crypto/ssh/agent
EPSS
Процентиль: 9%
0.00032
Низкий