ALT-PU-2019-1113-1
Closed vulnerabilities
Published: 2019-01-24
BDU:2019-00688
Уязвимость модуля crypto языка программирования Go, позволяющая нарушителю вызвать отказ в обслуживании
Severity: HIGH (7.5)
Vector: AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
References:
Published: 2019-01-24
Modified: 2024-11-21
Modified: 2024-11-21
CVE-2019-6486
Go before 1.10.8 and 1.11.x before 1.11.5 mishandles P-521 and P-384 elliptic curves, which allows attackers to cause a denial of service (CPU consumption) or possibly conduct ECDH private key recovery attacks.
Severity: HIGH (8.2)
Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H
References:
- openSUSE-SU-2019:1164
- openSUSE-SU-2019:1444
- openSUSE-SU-2019:1499
- openSUSE-SU-2019:1506
- 106740
- https://github.com/golang/go/commit/42b42f71cf8f5956c09e66230293dfb5db652360
- https://github.com/golang/go/issues/29903
- https://github.com/google/wycheproof
- https://groups.google.com/forum/#%21topic/golang-announce/mVeX35iXuSw
- [debian-lts-announce] 20190206 [SECURITY] [DLA 1664-1] golang security update
- DSA-4379
- DSA-4380
- openSUSE-SU-2019:1164
- DSA-4380
- DSA-4379
- [debian-lts-announce] 20190206 [SECURITY] [DLA 1664-1] golang security update
- https://groups.google.com/forum/#%21topic/golang-announce/mVeX35iXuSw
- https://github.com/google/wycheproof
- https://github.com/golang/go/issues/29903
- https://github.com/golang/go/commit/42b42f71cf8f5956c09e66230293dfb5db652360
- 106740
- openSUSE-SU-2019:1506
- openSUSE-SU-2019:1499
- openSUSE-SU-2019:1444