Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-6486

Опубликовано: 24 янв. 2019
Источник: redhat
CVSS3: 7.5

Описание

Go before 1.10.8 and 1.11.x before 1.11.5 mishandles P-521 and P-384 elliptic curves, which allows attackers to cause a denial of service (CPU consumption) or possibly conduct ECDH private key recovery attacks.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Ceph Storage 2golangAffected
Red Hat Ceph Storage 3golangAffected
Red Hat Enterprise Linux 7golangNot affected
Red Hat Enterprise Linux 8go-toolset:rhel8/golangWill not fix
Red Hat OpenShift Container Platform 3.10atomic-openshiftNot affected
Red Hat OpenShift Container Platform 3.11atomic-openshiftNot affected
Red Hat OpenShift Container Platform 3.2atomic-openshiftOut of support scope
Red Hat OpenShift Container Platform 3.3atomic-openshiftOut of support scope
Red Hat OpenShift Container Platform 3.4atomic-openshiftOut of support scope
Red Hat OpenShift Container Platform 3.5atomic-openshiftOut of support scope

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-20
https://bugzilla.redhat.com/show_bug.cgi?id=1668972golang: crypto/elliptic implementations of P-521 and P-384 elliptic curves allow for denial of service

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 8.2
ubuntu
больше 6 лет назад

Go before 1.10.8 and 1.11.x before 1.11.5 mishandles P-521 and P-384 elliptic curves, which allows attackers to cause a denial of service (CPU consumption) or possibly conduct ECDH private key recovery attacks.

CVSS3: 8.2
nvd
больше 6 лет назад

Go before 1.10.8 and 1.11.x before 1.11.5 mishandles P-521 and P-384 elliptic curves, which allows attackers to cause a denial of service (CPU consumption) or possibly conduct ECDH private key recovery attacks.

CVSS3: 8.2
debian
больше 6 лет назад

Go before 1.10.8 and 1.11.x before 1.11.5 mishandles P-521 and P-384 e ...

suse-cvrf
около 6 лет назад

Security update for go1.11

CVSS3: 8.2
github
около 3 лет назад

Go before 1.10.8 and 1.11.x before 1.11.5 mishandles P-521 and P-384 elliptic curves, which allows attackers to cause a denial of service (CPU consumption) or possibly conduct ECDH private key recovery attacks.

7.5 High

CVSS3