Vulnerability Description
Go before 1.12.11 and 1.3.x before 1.13.2 can panic upon an attempt to process network traffic containing an invalid DSA public key. There are several attack scenarios, such as traffic from a client to a server that verifies client certificates.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Golang | Go | >= 1.12, < 1.12.11 |
| Debian | Debian Linux | 9.0 |
| Fedoraproject | Fedora | 30 |
| Redhat | Developer Tools | 1.0 |
| Redhat | Enterprise Linux | 8.0 |
| Redhat | Enterprise Linux Server | 8.1 |
| Opensuse | Leap | 15.0 |
| Arista | Cloudvision Portal | >= 2018.1.0, <= 2018.2.3 |
| Arista | Terminattr | <= 1.7.2 |
| Arista | Eos | <= 4.23.1f |
| Arista | Mos | <= 0.25 |
Related Weaknesses (CWE)
References
- http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00043.htmlMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00044.htmlMailing ListThird Party Advisory
- https://access.redhat.com/errata/RHSA-2020:0101Third Party Advisory
- https://access.redhat.com/errata/RHSA-2020:0329Third Party Advisory
- https://github.com/golang/go/issues/34960ExploitIssue TrackingPatch
- https://groups.google.com/d/msg/golang-announce/lVEm7llp0w0/VbafyRkgCgAJRelease NotesThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2021/03/msg00014.htmlMailing ListThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2021/03/msg00015.htmlMailing ListThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://security.netapp.com/advisory/ntap-20191122-0005/Third Party Advisory
- https://www.arista.com/en/support/advisories-notices/security-advisories/10134-sThird Party Advisory
- https://www.debian.org/security/2019/dsa-4551Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00043.htmlMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00044.htmlMailing ListThird Party Advisory
FAQ
What is CVE-2019-17596?
CVE-2019-17596 is a vulnerability with a CVSS score of 7.5 (HIGH). Go before 1.12.11 and 1.3.x before 1.13.2 can panic upon an attempt to process network traffic containing an invalid DSA public key. There are several attack scenarios, such as traffic from a client t...
How severe is CVE-2019-17596?
CVE-2019-17596 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-17596?
Check the references section above for vendor advisories and patch information. Affected products include: Golang Go, Debian Debian Linux, Fedoraproject Fedora, Redhat Developer Tools, Redhat Enterprise Linux.