Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-vj2x-6gjj-jvh2

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 8.2

Описание

Go before 1.10.8 and 1.11.x before 1.11.5 mishandles P-521 and P-384 elliptic curves, which allows attackers to cause a denial of service (CPU consumption) or possibly conduct ECDH private key recovery attacks.

Go before 1.10.8 and 1.11.x before 1.11.5 mishandles P-521 and P-384 elliptic curves, which allows attackers to cause a denial of service (CPU consumption) or possibly conduct ECDH private key recovery attacks.

EPSS

Процентиль: 77%
0.0108
Низкий

8.2 High

CVSS3

Дефекты

CWE-770

Связанные уязвимости

CVSS3: 8.2
ubuntu
больше 6 лет назад

Go before 1.10.8 and 1.11.x before 1.11.5 mishandles P-521 and P-384 elliptic curves, which allows attackers to cause a denial of service (CPU consumption) or possibly conduct ECDH private key recovery attacks.

CVSS3: 7.5
redhat
больше 6 лет назад

Go before 1.10.8 and 1.11.x before 1.11.5 mishandles P-521 and P-384 elliptic curves, which allows attackers to cause a denial of service (CPU consumption) or possibly conduct ECDH private key recovery attacks.

CVSS3: 8.2
nvd
больше 6 лет назад

Go before 1.10.8 and 1.11.x before 1.11.5 mishandles P-521 and P-384 elliptic curves, which allows attackers to cause a denial of service (CPU consumption) or possibly conduct ECDH private key recovery attacks.

CVSS3: 8.2
debian
больше 6 лет назад

Go before 1.10.8 and 1.11.x before 1.11.5 mishandles P-521 and P-384 e ...

suse-cvrf
около 6 лет назад

Security update for go1.11

EPSS

Процентиль: 77%
0.0108
Низкий

8.2 High

CVSS3

Дефекты

CWE-770