HIGH · 7.5

CVE-2019-17596

Go before 1.12.11 and 1.3.x before 1.13.2 can panic upon an attempt to process network traffic containing an invalid DSA public key. There are several attack scenarios, such as traffic from a client t...

Vulnerability Description

Go before 1.12.11 and 1.3.x before 1.13.2 can panic upon an attempt to process network traffic containing an invalid DSA public key. There are several attack scenarios, such as traffic from a client to a server that verifies client certificates.

CVSS Score

7.5

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
NONE
Integrity
NONE
Availability
HIGH

Affected Products

VendorProductVersions
GolangGo>= 1.12, < 1.12.11
DebianDebian Linux9.0
FedoraprojectFedora30
RedhatDeveloper Tools1.0
RedhatEnterprise Linux8.0
RedhatEnterprise Linux Server8.1
OpensuseLeap15.0
AristaCloudvision Portal>= 2018.1.0, <= 2018.2.3
AristaTerminattr<= 1.7.2
AristaEos<= 4.23.1f
AristaMos<= 0.25

Related Weaknesses (CWE)

References

FAQ

What is CVE-2019-17596?

CVE-2019-17596 is a vulnerability with a CVSS score of 7.5 (HIGH). Go before 1.12.11 and 1.3.x before 1.13.2 can panic upon an attempt to process network traffic containing an invalid DSA public key. There are several attack scenarios, such as traffic from a client t...

How severe is CVE-2019-17596?

CVE-2019-17596 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2019-17596?

Check the references section above for vendor advisories and patch information. Affected products include: Golang Go, Debian Debian Linux, Fedoraproject Fedora, Redhat Developer Tools, Redhat Enterprise Linux.