Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-vj2x-6gjj-jvh2

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 8.2

Описание

Go before 1.10.8 and 1.11.x before 1.11.5 mishandles P-521 and P-384 elliptic curves, which allows attackers to cause a denial of service (CPU consumption) or possibly conduct ECDH private key recovery attacks.

Go before 1.10.8 and 1.11.x before 1.11.5 mishandles P-521 and P-384 elliptic curves, which allows attackers to cause a denial of service (CPU consumption) or possibly conduct ECDH private key recovery attacks.

EPSS

Процентиль: 84%
0.02397
Низкий

8.2 High

CVSS3

Дефекты

CWE-770

Связанные уязвимости

CVSS3: 8.2
ubuntu
почти 7 лет назад

Go before 1.10.8 and 1.11.x before 1.11.5 mishandles P-521 and P-384 elliptic curves, which allows attackers to cause a denial of service (CPU consumption) or possibly conduct ECDH private key recovery attacks.

CVSS3: 7.5
redhat
почти 7 лет назад

Go before 1.10.8 and 1.11.x before 1.11.5 mishandles P-521 and P-384 elliptic curves, which allows attackers to cause a denial of service (CPU consumption) or possibly conduct ECDH private key recovery attacks.

CVSS3: 8.2
nvd
почти 7 лет назад

Go before 1.10.8 and 1.11.x before 1.11.5 mishandles P-521 and P-384 elliptic curves, which allows attackers to cause a denial of service (CPU consumption) or possibly conduct ECDH private key recovery attacks.

msrc
2 месяца назад

Go before 1.10.8 and 1.11.x before 1.11.5 mishandles P-521 and P-384 elliptic curves, which allows attackers to cause a denial of service (CPU consumption) or possibly conduct ECDH private key recovery attacks.

CVSS3: 8.2
debian
почти 7 лет назад

Go before 1.10.8 and 1.11.x before 1.11.5 mishandles P-521 and P-384 e ...

EPSS

Процентиль: 84%
0.02397
Низкий

8.2 High

CVSS3

Дефекты

CWE-770