Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-hcg3-q754-cr77

Опубликовано: 12 апр. 2025
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

golang.org/x/crypto Vulnerable to Denial of Service (DoS) via Slow or Incomplete Key Exchange

SSH servers which implement file transfer protocols are vulnerable to a denial of service attack from clients which complete the key exchange slowly, or not at all, causing pending content to be read into memory, but never transmitted.

Пакеты

Наименование

golang.org/x/crypto

go
Затронутые версииВерсия исправления

< 0.35.0

0.35.0

EPSS

Процентиль: 18%
0.00058
Низкий

7.5 High

CVSS3

Дефекты

CWE-770

Связанные уязвимости

CVSS3: 7.5
ubuntu
4 месяца назад

SSH servers which implement file transfer protocols are vulnerable to a denial of service attack from clients which complete the key exchange slowly, or not at all, causing pending content to be read into memory, but never transmitted.

CVSS3: 7.5
redhat
4 месяца назад

SSH servers which implement file transfer protocols are vulnerable to a denial of service attack from clients which complete the key exchange slowly, or not at all, causing pending content to be read into memory, but never transmitted.

CVSS3: 7.5
nvd
4 месяца назад

SSH servers which implement file transfer protocols are vulnerable to a denial of service attack from clients which complete the key exchange slowly, or not at all, causing pending content to be read into memory, but never transmitted.

CVSS3: 7.5
msrc
3 месяца назад

Описание отсутствует

CVSS3: 7.5
debian
4 месяца назад

SSH servers which implement file transfer protocols are vulnerable to ...

EPSS

Процентиль: 18%
0.00058
Низкий

7.5 High

CVSS3

Дефекты

CWE-770