Описание
SSH Agent servers do not validate the size of messages when processing new identity requests, which may cause the program to panic if the message is malformed due to an out of bounds read.
Пакеты
| Пакет | Статус | Версия исправления | Релиз | Тип |
|---|---|---|---|---|
| golang-go.crypto | fixed | 1:0.45.0-1 | package | |
| golang-go.crypto | no-dsa | trixie | package | |
| golang-go.crypto | no-dsa | bookworm | package | |
| golang-go.crypto | postponed | bullseye | package |
Примечания
https://groups.google.com/g/golang-announce/c/w-oX3UxNcZA?pli=1
https://github.com/golang/go/issues/76364
Fixed by: https://github.com/golang/crypto/commit/f91f7a7c31bf90b39c1de895ad116a2bacc88748 (v0.45.0)
EPSS
Связанные уязвимости
SSH Agent servers do not validate the size of messages when processing new identity requests, which may cause the program to panic if the message is malformed due to an out of bounds read.
SSH Agent servers do not validate the size of messages when processing new identity requests, which may cause the program to panic if the message is malformed due to an out of bounds read.
golang.org/x/crypto/ssh/agent vulnerable to panic if message is malformed due to out of bounds read
Уязвимость сервера агента ssh-agent библиотеки для языка программирования Go crypto, позволяющая нарушителю вызвать отказ в обслуживании
EPSS