Описание
Certificate.Verify in crypto/x509 in Go 1.18.x before 1.18.1 can be caused to panic on macOS when presented with certain malformed certificates. This allows a remote TLS server to cause a TLS client to panic.
Ссылки
- Mailing ListVendor Advisory
- Mailing ListRelease NotesVendor Advisory
- Third Party Advisory
- Mailing ListVendor Advisory
- Mailing ListRelease NotesVendor Advisory
- Third Party Advisory
Уязвимые конфигурации
Одновременно
EPSS
7.5 High
CVSS3
5 Medium
CVSS2
Дефекты
Связанные уязвимости
Certificate.Verify in crypto/x509 in Go 1.18.x before 1.18.1 can be caused to panic on macOS when presented with certain malformed certificates. This allows a remote TLS server to cause a TLS client to panic.
Certificate.Verify in crypto/x509 in Go 1.18.x before 1.18.1 can be ca ...
Certificate.Verify in crypto/x509 in Go 1.18.x before 1.18.1 can be caused to panic on macOS when presented with certain malformed certificates. This allows a remote TLS server to cause a TLS client to panic.
ELSA-2022-17956: go-toolset:ol8addon security update (IMPORTANT)
EPSS
7.5 High
CVSS3
5 Medium
CVSS2