Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-j5w8-q4qc-rx2x

Опубликовано: 19 нояб. 2025
Источник: github
Github: Прошло ревью
CVSS3: 5.3

Описание

golang.org/x/crypto/ssh allows an attacker to cause unbounded memory consumption

SSH servers parsing GSSAPI authentication requests do not validate the number of mechanisms specified in the request, allowing an attacker to cause unbounded memory consumption.

Пакеты

Наименование

golang.org/x/crypto

go
Затронутые версииВерсия исправления

< 0.45.0

0.45.0

EPSS

Процентиль: 46%
0.00561
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-770

Связанные уязвимости

CVSS3: 5.3
ubuntu
10 месяцев назад

SSH servers parsing GSSAPI authentication requests do not validate the number of mechanisms specified in the request, allowing an attacker to cause unbounded memory consumption.

CVSS3: 5.3
redhat
10 месяцев назад

SSH servers parsing GSSAPI authentication requests do not validate the number of mechanisms specified in the request, allowing an attacker to cause unbounded memory consumption.

CVSS3: 5.3
nvd
10 месяцев назад

SSH servers parsing GSSAPI authentication requests do not validate the number of mechanisms specified in the request, allowing an attacker to cause unbounded memory consumption.

CVSS3: 5.3
debian
10 месяцев назад

SSH servers parsing GSSAPI authentication requests do not validate the ...

suse-cvrf
около 1 месяца назад

Security update for zk

EPSS

Процентиль: 46%
0.00561
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-770