GO-2023-1992
Dashboard / Vulnerabilities / GO-2023-1992
Summary: Misleading message verification in golang.org/x/crypto/openpgp/clearsign
Details: The clearsign package accepts some malformed messages, making it possible for an attacker to trick a human user (but not a Go program) into thinking unverified text is part of the message. With fix, messages with malformed headers in the SIGNED MESSAGE section are rejected.
References: https://go-review.git.corp.google.com/c/crypto/+/173778, https://go.googlesource.com/crypto/+/c05e17bb3b2dca130fc919668a96b4bec9eb9442, https://groups.google.com/d/msg/golang-openpgp/6vdgZoTgbIY/K6bBY9z3DAAJ
Affected packages
Package
Name: golang.org/x/crypto
Purl: pkg:golang/golang.org/x/crypto
Affected ranges
Type: SEMVER
Events:
Introduced- 0
Fixed -0.0.0-20190424203555-c05e17bb3b2d
Affected versions
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
