Back to search
CVE-2019-17596
Published: Oct 24, 2019
Modified: Aug 5, 2024
PUBLISHED
Description
Go before 1.12.11 and 1.3.x before 1.13.2 can panic upon an attempt to process network traffic containing an invalid DSA public key. There are several attack scenarios, such as traffic from a client to a server that verifies client certificates.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
https://groups.google.com/d/msg/golang-announce/lVEm7llp0w0/VbafyRkgCgAJ
x_refsource_CONFIRM
https://github.com/golang/go/issues/34960
x_refsource_CONFIRM
DSA-4551
vendor-advisory
x_refsource_DEBIAN
FEDORA-2019-4593120208
vendor-advisory
x_refsource_FEDORA
FEDORA-2019-34e097c66c
vendor-advisory
x_refsource_FEDORA
openSUSE-SU-2019:2522
vendor-advisory
x_refsource_SUSE
openSUSE-SU-2019:2521
vendor-advisory
x_refsource_SUSE
https://security.netapp.com/advisory/ntap-20191122-0005/
x_refsource_CONFIRM
RHSA-2020:0101
vendor-advisory
x_refsource_REDHAT
RHSA-2020:0329
vendor-advisory
x_refsource_REDHAT
[debian-lts-announce] 20210313 [SECURITY] [DLA 2591-1] golang-1.7 security update
mailing-list
x_refsource_MLIST
[debian-lts-announce] 20210313 [SECURITY] [DLA 2592-1] golang-1.8 security update
mailing-list
x_refsource_MLIST
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now