Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-9283

Опубликовано: 21 фев. 2020
Источник: redhat
CVSS3: 7.5
EPSS Средний

Описание

golang.org/x/crypto before v0.0.0-20200220183623-bac4c82f6975 for Go allows a panic during signature verification in the golang.org/x/crypto/ssh package. A client can attack an SSH server that accepts public keys. Also, a server can attack any SSH client.

A denial of service vulnerability was found in the SSH package of the golang.org/x/crypto library. An attacker could exploit this flaw by supplying crafted SSH ed25519 keys to cause a crash in applications that use this package as either an SSH client or server.

Отчет

OpenShift Container Platform uses the vulnerable library in a number of components but strictly as an SSH client. The severity of this vulnerability is reduced for clients as it requires connections to malicious SSH servers, with the maximum impact only a client crash. This vulnerability is rated Low for OpenShift Container Platform.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
OpenShift Service Mesh 1jaegerOut of support scope
OpenShift Service Mesh 1jaeger-operatorOut of support scope
Red Hat Enterprise Linux 7gomtreeNot affected
Red Hat OpenShift Container Platform 3.11atomic-openshiftWill not fix
Red Hat OpenShift Container Platform 3.11atomic-openshift-cluster-autoscalerWill not fix
Red Hat OpenShift Container Platform 3.11atomic-openshift-deschedulerWill not fix
Red Hat OpenShift Container Platform 3.11golang-github-openshift-oauth-proxyWill not fix
Red Hat OpenShift Container Platform 3.11openshift-enterprise-cluster-capacityWill not fix
Red Hat OpenShift Container Platform 4openshift4/ose-baremetal-installer-rhel8Fix deferred
Red Hat OpenShift Container Platform 4openshift4/ose-baremetal-machine-controllersFix deferred

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-130
https://bugzilla.redhat.com/show_bug.cgi?id=1804533golang.org/x/crypto: Processing of crafted ssh-ed25519 public keys allows for panic

EPSS

Процентиль: 95%
0.18682
Средний

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 6 лет назад

golang.org/x/crypto before v0.0.0-20200220183623-bac4c82f6975 for Go allows a panic during signature verification in the golang.org/x/crypto/ssh package. A client can attack an SSH server that accepts public keys. Also, a server can attack any SSH client.

CVSS3: 7.5
nvd
почти 6 лет назад

golang.org/x/crypto before v0.0.0-20200220183623-bac4c82f6975 for Go allows a panic during signature verification in the golang.org/x/crypto/ssh package. A client can attack an SSH server that accepts public keys. Also, a server can attack any SSH client.

CVSS3: 7.5
debian
почти 6 лет назад

golang.org/x/crypto before v0.0.0-20200220183623-bac4c82f6975 for Go a ...

CVSS3: 7.5
github
больше 4 лет назад

Improper Verification of Cryptographic Signature in golang.org/x/crypto

EPSS

Процентиль: 95%
0.18682
Средний

7.5 High

CVSS3