GO-2023-2000
Dashboard / Vulnerabilities / GO-2023-2000
GO-2023-2000
Published: 8 Aug 2023Last Modified: 20 May 2024
Aliases:
Summary: Large RSA keys can cause high resource usage in github.com/libp2p/go-libp2p
Details: Large RSA keys can lead to resource exhaustion attacks. With fix, the size of RSA keys transmitted during handshakes is restricted to <= 8192 bits.
References: https://github.com/libp2p/go-libp2p/security/advisories/GHSA-876p-8259-xjgg, https://go.dev/issue/61460, https://github.com/libp2p/go-libp2p/commit/0cce607219f3710addc7e18672cffd1f1d912fbb
Affected packages
Package
Name: github.com/libp2p/go-libp2p
Purl: pkg:golang/github.com/libp2p/go-libp2p
Affected ranges
Type: SEMVER
Events:
Introduced- 0
Fixed -0.27.8
Affected versions
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
