UBUNTU-CVE-2022-30629
Dashboard / Vulnerabilities / UBUNTU-CVE-2022-30629
UBUNTU-CVE-2022-30629
Summary:
Details: Non-random values for ticket_age_add in session tickets in crypto/tls before Go 1.17.11 and Go 1.18.3 allow an attacker that can observe TLS handshakes to correlate successive connections by comparing ticket ages during session resumption.
References: https://ubuntu.com/security/CVE-2022-30629, https://groups.google.com/g/golang-announce/c/TzIC9-t8Ytg, https://go.dev/issue/52814, https://github.com/golang/go/commit/c838098c327a1b6d63446f4722e943b02d235d78, https://github.com/golang/go/commit/c15a8e2dbb5ac376a6ed890735341b812d6b965c, https://ubuntu.com/security/notices/USN-6038-1, https://ubuntu.com/security/notices/USN-6038-2, https://www.cve.org/CVERecord?id=CVE-2022-30629
Affected packages
Package
Name: golang-1.13
Purl: pkg:deb/ubuntu/[email protected]~16.04.3+esm3?arch=source&distro=esm-apps/xenial
Affected ranges
Type: ECOSYSTEM
Events:
