Insecure digital certificates In golang-1.24
Description
Using ParsePKCS1PrivateKey to parse a RSA key that is missing the CRT values would panic when verifying that the key is well formed.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
debian 13 | 1.24~rc2-1 | ||
go | 1.24.0-rc.2 |
Aliases
1. 2. 3. 4. 5. 6. 7.
References
1. 2. 3.