UBUNTU-CVE-2016-3959

    Dashboard / Vulnerabilities / UBUNTU-CVE-2016-3959

    UBUNTU-CVE-2016-3959

    Published: 23 May 2016Last Modified: 16 Jul 2025
    Upstream:

    Summary:

    Details: The Verify function in crypto/dsa/dsa.go in Go before 1.5.4 and 1.6.x before 1.6.1 does not properly check parameters passed to the big integer library, which might allow remote attackers to cause a denial of service (infinite loop) via a crafted public key to a program that uses HTTPS client certificates or SSH server libraries.

    Affected packages

    Package

    Name: golang-1.6

    Purl: pkg:deb/ubuntu/[email protected]?arch=source&distro=xenial

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -1.6.1-0ubuntu1

    Affected versions

    1.6-0ubuntu1

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High