Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2019-11840

Опубликовано: 09 мая 2019
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 4.3
CVSS3: 5.9

Описание

An issue was discovered in the supplementary Go cryptography library, golang.org/x/crypto, before v0.0.0-20190320223903-b7391e95e576. A flaw was found in the amd64 implementation of the golang.org/x/crypto/salsa20 and golang.org/x/crypto/salsa20/salsa packages. If more than 256 GiB of keystream is generated, or if the counter otherwise grows greater than 32 bits, the amd64 implementation will first generate incorrect output, and then cycle back to previously generated keystream. Repeated keystream bytes can lead to loss of confidentiality in encryption applications, or to predictability in CSPRNG applications.

РелизСтатусПримечание
bionic

ignored

end of standard support, was needed
cosmic

ignored

end of life
devel

not-affected

1:0.0~git20200221.2aa609c-1
disco

ignored

end of life
eoan

ignored

end of life
esm-apps/bionic

needed

esm-apps/focal

not-affected

1:0.0~git20200221.2aa609c-1
esm-apps/jammy

not-affected

1:0.0~git20200221.2aa609c-1
esm-apps/noble

not-affected

1:0.0~git20200221.2aa609c-1
esm-infra-legacy/trusty

DNE

Показывать по

РелизСтатусПримечание
bionic

not-affected

code-not-compiled
cosmic

not-affected

code-not-present
disco

not-affected

code-not-present
eoan

not-affected

code-not-present
esm-apps/focal

not-affected

code-not-present
esm-infra-legacy/trusty

DNE

esm-infra/bionic

not-affected

code-not-compiled
esm-infra/xenial

not-affected

code-not-compiled
focal

not-affected

code-not-present
groovy

not-affected

code-not-present

Показывать по

РелизСтатусПримечание
bionic

ignored

cosmic

ignored

devel

ignored

disco

ignored

eoan

ignored

esm-infra-legacy/trusty

DNE

esm-infra/bionic

ignored

esm-infra/focal

ignored

esm-infra/xenial

ignored

focal

ignored

Показывать по

EPSS

Процентиль: 86%
0.02757
Низкий

4.3 Medium

CVSS2

5.9 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.9
redhat
почти 7 лет назад

An issue was discovered in the supplementary Go cryptography library, golang.org/x/crypto, before v0.0.0-20190320223903-b7391e95e576. A flaw was found in the amd64 implementation of the golang.org/x/crypto/salsa20 and golang.org/x/crypto/salsa20/salsa packages. If more than 256 GiB of keystream is generated, or if the counter otherwise grows greater than 32 bits, the amd64 implementation will first generate incorrect output, and then cycle back to previously generated keystream. Repeated keystream bytes can lead to loss of confidentiality in encryption applications, or to predictability in CSPRNG applications.

CVSS3: 5.9
nvd
больше 6 лет назад

An issue was discovered in the supplementary Go cryptography library, golang.org/x/crypto, before v0.0.0-20190320223903-b7391e95e576. A flaw was found in the amd64 implementation of the golang.org/x/crypto/salsa20 and golang.org/x/crypto/salsa20/salsa packages. If more than 256 GiB of keystream is generated, or if the counter otherwise grows greater than 32 bits, the amd64 implementation will first generate incorrect output, and then cycle back to previously generated keystream. Repeated keystream bytes can lead to loss of confidentiality in encryption applications, or to predictability in CSPRNG applications.

CVSS3: 5.9
debian
больше 6 лет назад

An issue was discovered in the supplementary Go cryptography library, ...

CVSS3: 5.9
github
больше 3 лет назад

golang.org/x/crypto/salsa20/salsa uses insufficiently random values

EPSS

Процентиль: 86%
0.02757
Низкий

4.3 Medium

CVSS2

5.9 Medium

CVSS3