Insecure digital certificates In golang.org/x/crypto
Description
Improper Verification of Cryptographic Signature in golang.org/x/crypto golang.org/x/crypto before v0.0.0-20200220183623-bac4c82f6975 for Go allows a panic during signature verification in the golang.org/x/crypto/ssh package. A client can attack an SSH server that accepts public keys. Also, a server can attack any SSH client.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
go | 0.0.0-20200220183623-bac4c82f6975 | ||
debian 14 | 1:0.0~git20200221.2aa609c-1 | ||
debian 13 | 1:0.0~git20200221.2aa609c-1 | ||
debian 11 | 1:0.0~git20200221.2aa609c-1 | ||
debian 12 | 1:0.0~git20200221.2aa609c-1 |
Aliases
1. 2. 3. 4. 5. 6. 7. 8. 9.
References
1. 2. 3. 4. 5. 6. 7. 8. 9.