GO-2022-0229
Dashboard / Vulnerabilities / GO-2022-0229
Summary: Panic in certificate parsing in crypto/x509 and golang.org/x/crypto/cryptobyte
Details: On 32-bit architectures, a malformed input to crypto/x509 or the ASN.1 parsing functions of golang.org/x/crypto/cryptobyte can lead to a panic. The malformed certificate can be delivered via a crypto/tls connection to a client, or to a server that accepts client certificates. net/http clients can be made to crash by an HTTPS server, while net/http servers that accept client certificates will recover the panic and are unaffected.
References: https://go.dev/cl/216680, https://go.googlesource.com/go/+/b13ce14c4a6aa59b7b041ad2b6eed2d23e15b574, https://go.dev/cl/216677, https://go.dev/issue/36837, https://groups.google.com/g/golang-announce/c/Hsw4mHYc470
Affected packages
Package
Name: stdlib
Purl: pkg:golang/stdlib
Affected ranges
Type: SEMVER
Events:
