Описание
Previously, a revoked 'SignatureKey' belonging to a CA was not correctly checked for revocation. Now, both the 'key' and 'key.SignatureKey' are checked for @revoked.
| Релиз | Статус | Примечание |
|---|---|---|
| devel | not-affected | 0.52.0-1 |
| esm-apps/bionic | released | 1:0.0~git20170629.0.5ef0053-2ubuntu0.1~esm2 |
| esm-apps/focal | released | 1:0.0~git20200221.2aa609c-1ubuntu0.1~esm2 |
| esm-apps/jammy | released | 1:0.0~git20211202.5770296-1ubuntu0.1~esm2 |
| esm-apps/noble | released | 1:0.19.0-1ubuntu0.1~esm2 |
| esm-apps/resolute | released | 1:0.47.0-1ubuntu0.1~esm1 |
| esm-infra-legacy/xenial | not-affected | code not present |
| jammy | needed | |
| noble | needed | |
| questing | ignored | end of life, was needed |
Показывать по
| Релиз | Статус | Примечание |
|---|---|---|
| devel | not-affected | code not present |
| esm-apps-legacy/xenial | not-affected | code not present |
| esm-apps/bionic | not-affected | code not present |
| esm-infra/focal | not-affected | code not present |
| jammy | not-affected | code not present |
| noble | not-affected | code not present |
| questing | not-affected | code not present |
| resolute | not-affected | code not present |
| upstream | needs-triage |
Показывать по
| Релиз | Статус | Примечание |
|---|---|---|
| devel | DNE | |
| esm-apps/focal | not-affected | code-not-present |
| esm-infra-legacy/xenial | released | 2.0.11-0ubuntu1~16.04.4+esm3 |
| esm-infra/bionic | released | 3.0.3-0ubuntu1~18.04.2+esm3 |
| jammy | DNE | |
| noble | DNE | |
| questing | DNE | |
| resolute | DNE | |
| upstream | needs-triage |
Показывать по
| Релиз | Статус | Примечание |
|---|---|---|
| devel | needs-triage | |
| esm-infra-legacy/xenial | needs-triage | |
| esm-infra/bionic | needs-triage | |
| esm-infra/focal | needs-triage | |
| jammy | needs-triage | |
| noble | needs-triage | |
| questing | ignored | end of life, was needs-triage |
| resolute | needs-triage | |
| snap | needs-triage | |
| upstream | needs-triage |
Показывать по
Ссылки на источники
9.1 Critical
CVSS3
Связанные уязвимости
Previously, a revoked 'SignatureKey' belonging to a CA was not correctly checked for revocation. Now, both the 'key' and 'key.SignatureKey' are checked for @revoked.
Previously, a revoked 'SignatureKey' belonging to a CA was not correctly checked for revocation. Now, both the 'key' and 'key.SignatureKey' are checked for @revoked.
Invoking auth bypass via unenforced @revoked status in golang.org/x/crypto/ssh/knownhosts
Previously, a revoked 'SignatureKey' belonging to a CA was not correct ...
9.1 Critical
CVSS3