7.5
CVE-2019-17596
- EPSS 4.69%
- Veröffentlicht 24.10.2019 22:15:10
- Zuletzt bearbeitet 21.11.2024 04:32:36
- Erkennungen
Go before 1.12.11 and 1.3.x before 1.13.2 can panic upon an attempt to process network traffic containing an invalid DSA public key. There are several attack scenarios, such as traffic from a client to a server that verifies client certificates.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Debian ≫ Debian Linux Version 9.0
Debian ≫ Debian Linux Version 10.0
Fedoraproject ≫ Fedora Version 30
Fedoraproject ≫ Fedora Version 31
Redhat ≫ Developer Tools Version 1.0
Redhat ≫ Enterprise Linux Version 8.0
Redhat ≫ Enterprise Linux Server Version 8.1
Arista ≫ Cloudvision Portal Version >= 2018.1.0 <= 2018.2.3
Arista ≫ Cloudvision Portal Version 2019.1.0
Arista ≫ Cloudvision Portal Version 2019.1.1
Arista ≫ Cloudvision Portal Version 2019.1.2
Arista ≫ Terminattr Version <= 1.7.2
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 4.69% | 0.906 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
|
| NIST | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:N/I:N/A:P
|
CWE-436 Interpretation Conflict
Product A handles inputs or steps differently than Product B, which causes A to perform incorrect actions based on its perception of B's state.
https://lists.debian.org/debian-lts-announce/2021/03/msg00014.html
https://lists.debian.org/debian-lts-announce/2021/03/msg00015.html
http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00043.html
http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00044.html
https://access.redhat.com/errata/RHSA-2020:0101
https://access.redhat.com/errata/RHSA-2020:0329
https://github.com/golang/go/issues/34960
https://groups.google.com/d/msg/golang-announce/lVEm7llp0w0/VbafyRkgCgAJ
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/5VS3HPSE25ZSGS4RSOTADC67YNOHIGVV/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WVOWGM7IQGRO7DS2MCUMYZRQ4TYOZNAS/
https://security.netapp.com/advisory/ntap-20191122-0005/
https://www.arista.com/en/support/advisories-notices/security-advisories/10134-security-advisory-46
https://www.debian.org/security/2019/dsa-4551