Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

rocky логотип

RLSA-2024:7502

Опубликовано: 25 окт. 2024
Источник: rocky
Оценка: Moderate

Описание

Moderate: go-toolset:rhel8 security update

Go Toolset provides the Go programming language tools and libraries. Go is alternatively known as golang.

Security Fix(es):

  • golang-fips: Golang FIPS zeroed buffer (CVE-2024-9355)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Затронутые продукты

  • Rocky Linux 8

НаименованиеАрхитектураРелизRPM
delvex86_644.module+el8.10.0+1868+7f5969f2delve-1.21.2-4.module+el8.10.0+1868+7f5969f2.x86_64.rpm
golangx86_643.module+el8.10.0+1873+81c21cb9golang-1.21.13-3.module+el8.10.0+1873+81c21cb9.x86_64.rpm
golang-binx86_643.module+el8.10.0+1873+81c21cb9golang-bin-1.21.13-3.module+el8.10.0+1873+81c21cb9.x86_64.rpm
golang-docsnoarch3.module+el8.10.0+1873+81c21cb9golang-docs-1.21.13-3.module+el8.10.0+1873+81c21cb9.noarch.rpm
golang-docsnoarch3.module+el8.10.0+1873+81c21cb9golang-docs-1.21.13-3.module+el8.10.0+1873+81c21cb9.noarch.rpm
golang-miscnoarch3.module+el8.10.0+1873+81c21cb9golang-misc-1.21.13-3.module+el8.10.0+1873+81c21cb9.noarch.rpm
golang-miscnoarch3.module+el8.10.0+1873+81c21cb9golang-misc-1.21.13-3.module+el8.10.0+1873+81c21cb9.noarch.rpm
golang-srcnoarch3.module+el8.10.0+1873+81c21cb9golang-src-1.21.13-3.module+el8.10.0+1873+81c21cb9.noarch.rpm
golang-srcnoarch3.module+el8.10.0+1873+81c21cb9golang-src-1.21.13-3.module+el8.10.0+1873+81c21cb9.noarch.rpm
golang-testsnoarch3.module+el8.10.0+1873+81c21cb9golang-tests-1.21.13-3.module+el8.10.0+1873+81c21cb9.noarch.rpm

Показывать по

Связанные CVE

Исправления

Связанные уязвимости

CVSS3: 6.5
redhat
около 1 года назад

A vulnerability was found in Golang FIPS OpenSSL. This flaw allows a malicious user to randomly cause an uninitialized buffer length variable with a zeroed buffer to be returned in FIPS mode. It may also be possible to force a false positive match between non-equal hashes when comparing a trusted computed hmac sum to an untrusted input sum if an attacker can send a zeroed buffer in place of a pre-computed sum.  It is also possible to force a derived key to be all zeros instead of an unpredictable value.  This may have follow-on implications for the Go TLS stack.

CVSS3: 6.5
nvd
около 1 года назад

A vulnerability was found in Golang FIPS OpenSSL. This flaw allows a malicious user to randomly cause an uninitialized buffer length variable with a zeroed buffer to be returned in FIPS mode. It may also be possible to force a false positive match between non-equal hashes when comparing a trusted computed hmac sum to an untrusted input sum if an attacker can send a zeroed buffer in place of a pre-computed sum.  It is also possible to force a derived key to be all zeros instead of an unpredictable value.  This may have follow-on implications for the Go TLS stack.

CVSS3: 6.5
msrc
5 месяцев назад

Описание отсутствует

rocky
около 1 года назад

Moderate: grafana-pcp security update

rocky
около 1 года назад

Moderate: golang security update