UBUNTU-CVE-2021-34558
Dashboard / Vulnerabilities / UBUNTU-CVE-2021-34558
Summary:
Details: The crypto/tls package of Go through 1.16.5 does not properly assert that the type of public key in an X.509 certificate matches the expected type when doing a RSA based key exchange, allowing a malicious TLS server to cause a TLS client to panic.
References: https://ubuntu.com/security/CVE-2021-34558, https://github.com/golang/go/issues/47143, https://github.com/golang/go/commit/58bc454a11d4b3dbc03f44dfcabb9068a9c076f4, https://groups.google.com/g/golang-announce, https://groups.google.com/g/golang-announce/c/n9FxMelZGAQ, https://golang.org/doc/devel/release#go1.16.minor, https://www.cve.org/CVERecord?id=CVE-2021-34558
Affected packages
Package
Name: golang-1.10
Purl: pkg:deb/ubuntu/[email protected]~14.04.1?arch=source&distro=trusty
Affected ranges
Type: ECOSYSTEM
Events:
