—
GO-2023-1866
Silver vulnerable to MitM attack against implants due to a cryptography vulnerability in github.com/bishopfox/sliver
Quick fix
GO-2023-1866 — github.com/bishopfox/sliver: upgrade to the fixed version with the command below.
go get github.com/bishopfox/sliver@v1.5.40Details
Silver vulnerable to MitM attack against implants due to a cryptography vulnerability in github.com/bishopfox/sliver
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/bishopfox/sliver
Introduced in:
1.5.0Fixed in: 1.5.40Fix
go get github.com/bishopfox/sliver@v1.5.40References
- https://github.com/BishopFox/sliver/security/advisories/GHSA-8jxm-xp43-qh3q[ADVISORY]
- https://github.com/advisories/GHSA-8jxm-xp43-qh3q[ADVISORY]
- https://nvd.nist.gov/vuln/detail/CVE-2023-34758[ADVISORY]
- https://nvd.nist.gov/vuln/detail/CVE-2023-35170[ADVISORY]
- https://github.com/BishopFox/sliver/blob/master/implant/sliver/cryptography/crypto.go[WEB]
- https://github.com/BishopFox/sliver/blob/master/implant/sliver/cryptography/implant.go[WEB]
- https://github.com/BishopFox/sliver/commit/2d1ea6192cac2ff9d6450b2d96043fdbf8561516[WEB]
- https://github.com/BishopFox/sliver/releases/tag/v1.5.40[WEB]
- https://github.com/tangent65536/Slivjacker[WEB]
- https://www.chtsecurity.com/news/04f41dcc-1851-463c-93bc-551323ad8091[WEB]