Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2025-61727

Опубликовано: 03 дек. 2025
Источник: debian

Описание

An excluded subdomain constraint in a certificate chain does not restrict the usage of wildcard SANs in the leaf certificate. For example a constraint that excludes the subdomain test.example.com does not prevent a leaf certificate from claiming the SAN *.example.com.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
golang-1.25unfixedpackage
golang-1.24unfixedpackage
golang-1.19removedpackage
golang-1.19no-dsabookwormpackage
golang-1.15removedpackage
golang-1.15postponedbullseyepackage

Примечания

  • https://groups.google.com/g/golang-announce/c/8FJoBkPddm4

  • https://github.com/golang/go/issues/76442

  • Fixed by: https://github.com/golang/go/commit/287017acebd27203aa3218abbd11ed65c2280cf8 (go1.25.5)

  • Fixed by: https://github.com/golang/go/commit/04db77a423cac75bb82cc9a6859991ae9c016344 (go1.24.11)

Связанные уязвимости

CVSS3: 6.5
ubuntu
около 1 месяца назад

An excluded subdomain constraint in a certificate chain does not restrict the usage of wildcard SANs in the leaf certificate. For example a constraint that excludes the subdomain test.example.com does not prevent a leaf certificate from claiming the SAN *.example.com.

CVSS3: 6.5
nvd
около 1 месяца назад

An excluded subdomain constraint in a certificate chain does not restrict the usage of wildcard SANs in the leaf certificate. For example a constraint that excludes the subdomain test.example.com does not prevent a leaf certificate from claiming the SAN *.example.com.

msrc
около 1 месяца назад

Improper application of excluded DNS name constraints when verifying wildcard names in crypto/x509

CVSS3: 6.5
github
около 1 месяца назад

An excluded subdomain constraint in a certificate chain does not restrict the usage of wildcard SANs in the leaf certificate. For example a constraint that excludes the subdomain test.example.com does not prevent a leaf certificate from claiming the SAN *.example.com.

CVSS3: 6.5
fstec
около 2 месяцев назад

Уязвимость языка программирования Go, связанная с недостатками процедуры авторизации, позволяющая нарушителю оказать воздействие на конфиденциальность и целостность защищаемой информации