GO-2020-0009
Dashboard / Vulnerabilities / GO-2020-0009
GO-2020-0009
Published: 14 Apr 2021Last Modified: 20 May 2024
Aliases:
Summary: Integer overflow in github.com/square/go-jose
Details: On 32-bit platforms an attacker can manipulate a ciphertext encrypted with AES-CBC with HMAC such that they can control how large the input buffer is when computing the HMAC authentication tag. This can can allow a manipulated ciphertext to be verified as authentic, opening the door for padding oracle attacks.
References: https://github.com/square/go-jose/commit/789a4c4bd4c118f7564954f441b29c153ccd6a96, https://www.openwall.com/lists/oss-security/2016/11/03/1
Affected packages
Package
Name: github.com/square/go-jose
Purl: pkg:golang/github.com/square/go-jose
Affected ranges
Type: SEMVER
Events:
Introduced- 0
Fixed -0.0.0-20160903044734-789a4c4bd4c1
Affected versions
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
