Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-17596

Опубликовано: 17 окт. 2019
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

Go before 1.12.11 and 1.3.x before 1.13.2 can panic upon an attempt to process network traffic containing an invalid DSA public key. There are several attack scenarios, such as traffic from a client to a server that verifies client certificates.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Ceph Storage 2golangOut of support scope
Red Hat Ceph Storage 3golangAffected
Red Hat Ceph Storage 3grafanaNot affected
Red Hat Enterprise Linux 7golangOut of support scope
Red Hat OpenShift Container Platform 3.10atomic-openshiftOut of support scope
Red Hat OpenShift Container Platform 3.11atomic-openshiftOut of support scope
Red Hat OpenShift Container Platform 3.9atomic-openshiftOut of support scope
Red Hat Storage 3golangAffected
Red Hat Storage 3grafanaNot affected
Red Hat Storage 3heketiNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-295
https://bugzilla.redhat.com/show_bug.cgi?id=1763310golang: invalid public key causes panic in dsa.Verify

EPSS

Процентиль: 90%
0.05915
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 5 лет назад

Go before 1.12.11 and 1.3.x before 1.13.2 can panic upon an attempt to process network traffic containing an invalid DSA public key. There are several attack scenarios, such as traffic from a client to a server that verifies client certificates.

CVSS3: 7.5
nvd
больше 5 лет назад

Go before 1.12.11 and 1.3.x before 1.13.2 can panic upon an attempt to process network traffic containing an invalid DSA public key. There are several attack scenarios, such as traffic from a client to a server that verifies client certificates.

CVSS3: 7.5
msrc
9 месяцев назад

Описание отсутствует

CVSS3: 7.5
debian
больше 5 лет назад

Go before 1.12.11 and 1.3.x before 1.13.2 can panic upon an attempt to ...

github
около 3 лет назад

Go before 1.12.11 and 1.3.x before 1.13.2 can panic upon an attempt to process network traffic containing an invalid DSA public key. There are several attack scenarios, such as traffic from a client to a server that verifies client certificates.

EPSS

Процентиль: 90%
0.05915
Низкий

7.5 High

CVSS3