Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-gcr4-wcqh-3624

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Go before 1.12.11 and 1.3.x before 1.13.2 can panic upon an attempt to process network traffic containing an invalid DSA public key. There are several attack scenarios, such as traffic from a client to a server that verifies client certificates.

Go before 1.12.11 and 1.3.x before 1.13.2 can panic upon an attempt to process network traffic containing an invalid DSA public key. There are several attack scenarios, such as traffic from a client to a server that verifies client certificates.

EPSS

Процентиль: 88%
0.04061
Низкий

Дефекты

CWE-436

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 6 лет назад

Go before 1.12.11 and 1.3.x before 1.13.2 can panic upon an attempt to process network traffic containing an invalid DSA public key. There are several attack scenarios, such as traffic from a client to a server that verifies client certificates.

CVSS3: 7.5
redhat
почти 6 лет назад

Go before 1.12.11 and 1.3.x before 1.13.2 can panic upon an attempt to process network traffic containing an invalid DSA public key. There are several attack scenarios, such as traffic from a client to a server that verifies client certificates.

CVSS3: 7.5
nvd
почти 6 лет назад

Go before 1.12.11 and 1.3.x before 1.13.2 can panic upon an attempt to process network traffic containing an invalid DSA public key. There are several attack scenarios, such as traffic from a client to a server that verifies client certificates.

CVSS3: 7.5
msrc
11 месяцев назад

Описание отсутствует

CVSS3: 7.5
debian
почти 6 лет назад

Go before 1.12.11 and 1.3.x before 1.13.2 can panic upon an attempt to ...

EPSS

Процентиль: 88%
0.04061
Низкий

Дефекты

CWE-436