Логотип exploitDog
bind:"CVE-2024-9355"
Консоль
Логотип exploitDog

exploitDog

bind:"CVE-2024-9355"

Количество 18

Количество 18

redhat логотип

CVE-2024-9355

около 1 года назад

A vulnerability was found in Golang FIPS OpenSSL. This flaw allows a malicious user to randomly cause an uninitialized buffer length variable with a zeroed buffer to be returned in FIPS mode. It may also be possible to force a false positive match between non-equal hashes when comparing a trusted computed hmac sum to an untrusted input sum if an attacker can send a zeroed buffer in place of a pre-computed sum.  It is also possible to force a derived key to be all zeros instead of an unpredictable value.  This may have follow-on implications for the Go TLS stack.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2024-9355

около 1 года назад

A vulnerability was found in Golang FIPS OpenSSL. This flaw allows a malicious user to randomly cause an uninitialized buffer length variable with a zeroed buffer to be returned in FIPS mode. It may also be possible to force a false positive match between non-equal hashes when comparing a trusted computed hmac sum to an untrusted input sum if an attacker can send a zeroed buffer in place of a pre-computed sum.  It is also possible to force a derived key to be all zeros instead of an unpredictable value.  This may have follow-on implications for the Go TLS stack.

CVSS3: 6.5
EPSS: Низкий
msrc логотип

CVE-2024-9355

5 месяцев назад

CVSS3: 6.5
EPSS: Низкий
rocky логотип

RLSA-2024:8847

около 1 года назад

Moderate: grafana-pcp security update

EPSS: Низкий
rocky логотип

RLSA-2024:7550

около 1 года назад

Moderate: golang security update

EPSS: Низкий
rocky логотип

RLSA-2024:7502

около 1 года назад

Moderate: go-toolset:rhel8 security update

EPSS: Низкий
github логотип

GHSA-3h3x-2hwv-hr52

около 1 года назад

Golang FIPS OpenSSL has a Use of Uninitialized Variable vulnerability

CVSS3: 6.5
EPSS: Низкий
oracle-oval логотип

ELSA-2024-8847

около 1 года назад

ELSA-2024-8847: grafana-pcp security update (MODERATE)

EPSS: Низкий
oracle-oval логотип

ELSA-2024-7550

около 1 года назад

ELSA-2024-7550: golang security update (MODERATE)

EPSS: Низкий
oracle-oval логотип

ELSA-2024-7502

около 1 года назад

ELSA-2024-7502: go-toolset:ol8 security update (MODERATE)

EPSS: Низкий
rocky логотип

RLSA-2024:8678

около 1 года назад

Important: grafana security update

EPSS: Низкий
rocky логотип

RLSA-2024:8327

около 1 года назад

Important: grafana security update

EPSS: Низкий
oracle-oval логотип

ELSA-2024-8678

около 1 года назад

ELSA-2024-8678: grafana security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2024-8327

около 1 года назад

ELSA-2024-8327: grafana security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2025-7118

7 месяцев назад

ELSA-2025-7118: osbuild and osbuild-composer security update (IMPORTANT)

EPSS: Низкий
rocky логотип

RLSA-2025:7256

2 месяца назад

Moderate: git-lfs security update

EPSS: Низкий
oracle-oval логотип

ELSA-2025-7256

7 месяцев назад

ELSA-2025-7256: git-lfs security update (MODERATE)

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2024:3911-1

около 1 года назад

Security update for govulncheck-vulndb

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2024-9355

A vulnerability was found in Golang FIPS OpenSSL. This flaw allows a malicious user to randomly cause an uninitialized buffer length variable with a zeroed buffer to be returned in FIPS mode. It may also be possible to force a false positive match between non-equal hashes when comparing a trusted computed hmac sum to an untrusted input sum if an attacker can send a zeroed buffer in place of a pre-computed sum.  It is also possible to force a derived key to be all zeros instead of an unpredictable value.  This may have follow-on implications for the Go TLS stack.

CVSS3: 6.5
0%
Низкий
около 1 года назад
nvd логотип
CVE-2024-9355

A vulnerability was found in Golang FIPS OpenSSL. This flaw allows a malicious user to randomly cause an uninitialized buffer length variable with a zeroed buffer to be returned in FIPS mode. It may also be possible to force a false positive match between non-equal hashes when comparing a trusted computed hmac sum to an untrusted input sum if an attacker can send a zeroed buffer in place of a pre-computed sum.  It is also possible to force a derived key to be all zeros instead of an unpredictable value.  This may have follow-on implications for the Go TLS stack.

CVSS3: 6.5
0%
Низкий
около 1 года назад
msrc логотип
CVSS3: 6.5
0%
Низкий
5 месяцев назад
rocky логотип
RLSA-2024:8847

Moderate: grafana-pcp security update

0%
Низкий
около 1 года назад
rocky логотип
RLSA-2024:7550

Moderate: golang security update

0%
Низкий
около 1 года назад
rocky логотип
RLSA-2024:7502

Moderate: go-toolset:rhel8 security update

0%
Низкий
около 1 года назад
github логотип
GHSA-3h3x-2hwv-hr52

Golang FIPS OpenSSL has a Use of Uninitialized Variable vulnerability

CVSS3: 6.5
0%
Низкий
около 1 года назад
oracle-oval логотип
ELSA-2024-8847

ELSA-2024-8847: grafana-pcp security update (MODERATE)

около 1 года назад
oracle-oval логотип
ELSA-2024-7550

ELSA-2024-7550: golang security update (MODERATE)

около 1 года назад
oracle-oval логотип
ELSA-2024-7502

ELSA-2024-7502: go-toolset:ol8 security update (MODERATE)

около 1 года назад
rocky логотип
RLSA-2024:8678

Important: grafana security update

около 1 года назад
rocky логотип
RLSA-2024:8327

Important: grafana security update

около 1 года назад
oracle-oval логотип
ELSA-2024-8678

ELSA-2024-8678: grafana security update (IMPORTANT)

около 1 года назад
oracle-oval логотип
ELSA-2024-8327

ELSA-2024-8327: grafana security update (IMPORTANT)

около 1 года назад
oracle-oval логотип
ELSA-2025-7118

ELSA-2025-7118: osbuild and osbuild-composer security update (IMPORTANT)

7 месяцев назад
rocky логотип
RLSA-2025:7256

Moderate: git-lfs security update

2 месяца назад
oracle-oval логотип
ELSA-2025-7256

ELSA-2025-7256: git-lfs security update (MODERATE)

7 месяцев назад
suse-cvrf логотип
SUSE-SU-2024:3911-1

Security update for govulncheck-vulndb

около 1 года назад

Уязвимостей на страницу