VDB
Sign up
—

GO-2021-0102

Panic in decryption in code.cloudfoundry.org/gorouter

Quick fix

GO-2021-0102 — code.cloudfoundry.org/gorouter: upgrade to the fixed version with the command below.

go get code.cloudfoundry.org/gorouter@v0.0.0-20191101214924-b1b5c44e050f

Details

Due to improper input validation, a maliciously crafted input can cause a panic, due to incorrect nonce size. If this package is used to decrypt user supplied messages without checking the size of supplied nonces, this may be used as a vector for a denial of service attack.

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/code.cloudfoundry.org/gorouter
Introduced in: 0Fixed in: 0.0.0-20191101214924-b1b5c44e050f
Fixgo get code.cloudfoundry.org/gorouter@v0.0.0-20191101214924-b1b5c44e050f
Go/github.com/cloudfoundry/gorouter
Introduced in: 0Fixed in: 0.0.0-20191101214924-b1b5c44e050f
Fixgo get github.com/cloudfoundry/gorouter@v0.0.0-20191101214924-b1b5c44e050f

References