Логотип exploitDog
bind:CVE-2024-9355
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-9355

Количество 16

Количество 16

redhat логотип

CVE-2024-9355

около 1 года назад

A vulnerability was found in Golang FIPS OpenSSL. This flaw allows a malicious user to randomly cause an uninitialized buffer length variable with a zeroed buffer to be returned in FIPS mode. It may also be possible to force a false positive match between non-equal hashes when comparing a trusted computed hmac sum to an untrusted input sum if an attacker can send a zeroed buffer in place of a pre-computed sum.  It is also possible to force a derived key to be all zeros instead of an unpredictable value.  This may have follow-on implications for the Go TLS stack.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2024-9355

около 1 года назад

A vulnerability was found in Golang FIPS OpenSSL. This flaw allows a malicious user to randomly cause an uninitialized buffer length variable with a zeroed buffer to be returned in FIPS mode. It may also be possible to force a false positive match between non-equal hashes when comparing a trusted computed hmac sum to an untrusted input sum if an attacker can send a zeroed buffer in place of a pre-computed sum.  It is also possible to force a derived key to be all zeros instead of an unpredictable value.  This may have follow-on implications for the Go TLS stack.

CVSS3: 6.5
EPSS: Низкий
msrc логотип

CVE-2024-9355

3 месяца назад

CVSS3: 6.5
EPSS: Низкий
rocky логотип

RLSA-2024:8847

12 месяцев назад

Moderate: grafana-pcp security update

EPSS: Низкий
rocky логотип

RLSA-2024:7550

12 месяцев назад

Moderate: golang security update

EPSS: Низкий
github логотип

GHSA-3h3x-2hwv-hr52

около 1 года назад

Golang FIPS OpenSSL has a Use of Uninitialized Variable vulnerability

CVSS3: 6.5
EPSS: Низкий
oracle-oval логотип

ELSA-2024-8847

12 месяцев назад

ELSA-2024-8847: grafana-pcp security update (MODERATE)

EPSS: Низкий
oracle-oval логотип

ELSA-2024-7550

около 1 года назад

ELSA-2024-7550: golang security update (MODERATE)

EPSS: Низкий
oracle-oval логотип

ELSA-2024-7502

около 1 года назад

ELSA-2024-7502: go-toolset:ol8 security update (MODERATE)

EPSS: Низкий
rocky логотип

RLSA-2024:8678

12 месяцев назад

Important: grafana security update

EPSS: Низкий
rocky логотип

RLSA-2024:8327

12 месяцев назад

Important: grafana security update

EPSS: Низкий
oracle-oval логотип

ELSA-2024-8678

12 месяцев назад

ELSA-2024-8678: grafana security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2024-8327

12 месяцев назад

ELSA-2024-8327: grafana security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2025-7118

5 месяцев назад

ELSA-2025-7118: osbuild and osbuild-composer security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2025-7256

5 месяцев назад

ELSA-2025-7256: git-lfs security update (MODERATE)

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2024:3911-1

12 месяцев назад

Security update for govulncheck-vulndb

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2024-9355

A vulnerability was found in Golang FIPS OpenSSL. This flaw allows a malicious user to randomly cause an uninitialized buffer length variable with a zeroed buffer to be returned in FIPS mode. It may also be possible to force a false positive match between non-equal hashes when comparing a trusted computed hmac sum to an untrusted input sum if an attacker can send a zeroed buffer in place of a pre-computed sum.  It is also possible to force a derived key to be all zeros instead of an unpredictable value.  This may have follow-on implications for the Go TLS stack.

CVSS3: 6.5
0%
Низкий
около 1 года назад
nvd логотип
CVE-2024-9355

A vulnerability was found in Golang FIPS OpenSSL. This flaw allows a malicious user to randomly cause an uninitialized buffer length variable with a zeroed buffer to be returned in FIPS mode. It may also be possible to force a false positive match between non-equal hashes when comparing a trusted computed hmac sum to an untrusted input sum if an attacker can send a zeroed buffer in place of a pre-computed sum.  It is also possible to force a derived key to be all zeros instead of an unpredictable value.  This may have follow-on implications for the Go TLS stack.

CVSS3: 6.5
0%
Низкий
около 1 года назад
msrc логотип
CVSS3: 6.5
0%
Низкий
3 месяца назад
rocky логотип
RLSA-2024:8847

Moderate: grafana-pcp security update

0%
Низкий
12 месяцев назад
rocky логотип
RLSA-2024:7550

Moderate: golang security update

0%
Низкий
12 месяцев назад
github логотип
GHSA-3h3x-2hwv-hr52

Golang FIPS OpenSSL has a Use of Uninitialized Variable vulnerability

CVSS3: 6.5
0%
Низкий
около 1 года назад
oracle-oval логотип
ELSA-2024-8847

ELSA-2024-8847: grafana-pcp security update (MODERATE)

12 месяцев назад
oracle-oval логотип
ELSA-2024-7550

ELSA-2024-7550: golang security update (MODERATE)

около 1 года назад
oracle-oval логотип
ELSA-2024-7502

ELSA-2024-7502: go-toolset:ol8 security update (MODERATE)

около 1 года назад
rocky логотип
RLSA-2024:8678

Important: grafana security update

12 месяцев назад
rocky логотип
RLSA-2024:8327

Important: grafana security update

12 месяцев назад
oracle-oval логотип
ELSA-2024-8678

ELSA-2024-8678: grafana security update (IMPORTANT)

12 месяцев назад
oracle-oval логотип
ELSA-2024-8327

ELSA-2024-8327: grafana security update (IMPORTANT)

12 месяцев назад
oracle-oval логотип
ELSA-2025-7118

ELSA-2025-7118: osbuild and osbuild-composer security update (IMPORTANT)

5 месяцев назад
oracle-oval логотип
ELSA-2025-7256

ELSA-2025-7256: git-lfs security update (MODERATE)

5 месяцев назад
suse-cvrf логотип
SUSE-SU-2024:3911-1

Security update for govulncheck-vulndb

12 месяцев назад

Уязвимостей на страницу