Логотип exploitDog
bind:CVE-2024-9355
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-9355

Количество 16

Количество 16

redhat логотип

CVE-2024-9355

9 месяцев назад

A vulnerability was found in Golang FIPS OpenSSL. This flaw allows a malicious user to randomly cause an uninitialized buffer length variable with a zeroed buffer to be returned in FIPS mode. It may also be possible to force a false positive match between non-equal hashes when comparing a trusted computed hmac sum to an untrusted input sum if an attacker can send a zeroed buffer in place of a pre-computed sum.  It is also possible to force a derived key to be all zeros instead of an unpredictable value.  This may have follow-on implications for the Go TLS stack.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2024-9355

9 месяцев назад

A vulnerability was found in Golang FIPS OpenSSL. This flaw allows a malicious user to randomly cause an uninitialized buffer length variable with a zeroed buffer to be returned in FIPS mode. It may also be possible to force a false positive match between non-equal hashes when comparing a trusted computed hmac sum to an untrusted input sum if an attacker can send a zeroed buffer in place of a pre-computed sum.  It is also possible to force a derived key to be all zeros instead of an unpredictable value.  This may have follow-on implications for the Go TLS stack.

CVSS3: 6.5
EPSS: Низкий
msrc логотип

CVE-2024-9355

6 месяцев назад

CVSS3: 6.5
EPSS: Низкий
rocky логотип

RLSA-2024:8847

7 месяцев назад

Moderate: grafana-pcp security update

EPSS: Низкий
rocky логотип

RLSA-2024:7550

8 месяцев назад

Moderate: golang security update

EPSS: Низкий
github логотип

GHSA-3h3x-2hwv-hr52

9 месяцев назад

Golang FIPS OpenSSL has a Use of Uninitialized Variable vulnerability

CVSS3: 6.5
EPSS: Низкий
oracle-oval логотип

ELSA-2024-8847

8 месяцев назад

ELSA-2024-8847: grafana-pcp security update (MODERATE)

EPSS: Низкий
oracle-oval логотип

ELSA-2024-7550

9 месяцев назад

ELSA-2024-7550: golang security update (MODERATE)

EPSS: Низкий
oracle-oval логотип

ELSA-2024-7502

9 месяцев назад

ELSA-2024-7502: go-toolset:ol8 security update (MODERATE)

EPSS: Низкий
rocky логотип

RLSA-2024:8678

7 месяцев назад

Important: grafana security update

EPSS: Низкий
rocky логотип

RLSA-2024:8327

8 месяцев назад

Important: grafana security update

EPSS: Низкий
oracle-oval логотип

ELSA-2024-8678

8 месяцев назад

ELSA-2024-8678: grafana security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2024-8327

8 месяцев назад

ELSA-2024-8327: grafana security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2025-7118

около 1 месяца назад

ELSA-2025-7118: osbuild and osbuild-composer security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2025-7256

около 1 месяца назад

ELSA-2025-7256: git-lfs security update (MODERATE)

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2024:3911-1

8 месяцев назад

Security update for govulncheck-vulndb

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2024-9355

A vulnerability was found in Golang FIPS OpenSSL. This flaw allows a malicious user to randomly cause an uninitialized buffer length variable with a zeroed buffer to be returned in FIPS mode. It may also be possible to force a false positive match between non-equal hashes when comparing a trusted computed hmac sum to an untrusted input sum if an attacker can send a zeroed buffer in place of a pre-computed sum.  It is also possible to force a derived key to be all zeros instead of an unpredictable value.  This may have follow-on implications for the Go TLS stack.

CVSS3: 6.5
0%
Низкий
9 месяцев назад
nvd логотип
CVE-2024-9355

A vulnerability was found in Golang FIPS OpenSSL. This flaw allows a malicious user to randomly cause an uninitialized buffer length variable with a zeroed buffer to be returned in FIPS mode. It may also be possible to force a false positive match between non-equal hashes when comparing a trusted computed hmac sum to an untrusted input sum if an attacker can send a zeroed buffer in place of a pre-computed sum.  It is also possible to force a derived key to be all zeros instead of an unpredictable value.  This may have follow-on implications for the Go TLS stack.

CVSS3: 6.5
0%
Низкий
9 месяцев назад
msrc логотип
CVSS3: 6.5
0%
Низкий
6 месяцев назад
rocky логотип
RLSA-2024:8847

Moderate: grafana-pcp security update

0%
Низкий
7 месяцев назад
rocky логотип
RLSA-2024:7550

Moderate: golang security update

0%
Низкий
8 месяцев назад
github логотип
GHSA-3h3x-2hwv-hr52

Golang FIPS OpenSSL has a Use of Uninitialized Variable vulnerability

CVSS3: 6.5
0%
Низкий
9 месяцев назад
oracle-oval логотип
ELSA-2024-8847

ELSA-2024-8847: grafana-pcp security update (MODERATE)

8 месяцев назад
oracle-oval логотип
ELSA-2024-7550

ELSA-2024-7550: golang security update (MODERATE)

9 месяцев назад
oracle-oval логотип
ELSA-2024-7502

ELSA-2024-7502: go-toolset:ol8 security update (MODERATE)

9 месяцев назад
rocky логотип
RLSA-2024:8678

Important: grafana security update

7 месяцев назад
rocky логотип
RLSA-2024:8327

Important: grafana security update

8 месяцев назад
oracle-oval логотип
ELSA-2024-8678

ELSA-2024-8678: grafana security update (IMPORTANT)

8 месяцев назад
oracle-oval логотип
ELSA-2024-8327

ELSA-2024-8327: grafana security update (IMPORTANT)

8 месяцев назад
oracle-oval логотип
ELSA-2025-7118

ELSA-2025-7118: osbuild and osbuild-composer security update (IMPORTANT)

около 1 месяца назад
oracle-oval логотип
ELSA-2025-7256

ELSA-2025-7256: git-lfs security update (MODERATE)

около 1 месяца назад
suse-cvrf логотип
SUSE-SU-2024:3911-1

Security update for govulncheck-vulndb

8 месяцев назад

Уязвимостей на страницу