Back to search
CVE-2019-6486
Published: Jan 24, 2019
Modified: Aug 4, 2024
PUBLISHED
Description
Go before 1.10.8 and 1.11.x before 1.11.5 mishandles P-521 and P-384 elliptic curves, which allows attackers to cause a denial of service (CPU consumption) or possibly conduct ECDH private key recovery attacks.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
https://github.com/golang/go/issues/29903
x_refsource_CONFIRM
DSA-4380
vendor-advisory
x_refsource_DEBIAN
https://groups.google.com/forum/#%21topic/golang-announce/mVeX35iXuSw
x_refsource_CONFIRM
DSA-4379
vendor-advisory
x_refsource_DEBIAN
https://github.com/golang/go/commit/42b42f71cf8f5956c09e66230293dfb5db652360
x_refsource_CONFIRM
[debian-lts-announce] 20190206 [SECURITY] [DLA 1664-1] golang security update
mailing-list
x_refsource_MLIST
106740
vdb-entry
x_refsource_BID
https://github.com/google/wycheproof
x_refsource_MISC
openSUSE-SU-2019:1164
vendor-advisory
x_refsource_SUSE
openSUSE-SU-2019:1444
vendor-advisory
x_refsource_SUSE
openSUSE-SU-2019:1499
vendor-advisory
x_refsource_SUSE
openSUSE-SU-2019:1506
vendor-advisory
x_refsource_SUSE
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now