VDB
Sign up
HIGH7.5

GHSA-ffhg-7mh4-33c4

Improper Verification of Cryptographic Signature in golang.org/x/crypto

Quick fix

GHSA-ffhg-7mh4-33c4 — golang.org/x/crypto: upgrade to the fixed version with the command below.

go get golang.org/x/crypto@v0.0.0-20200220183623-bac4c82f6975

Details

golang.org/x/crypto before v0.0.0-20200220183623-bac4c82f6975 for Go allows a panic during signature verification in the golang.org/x/crypto/ssh package. A client can attack an SSH server that accepts public keys. Also, a server can attack any SSH client.

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/golang.org/x/crypto
Introduced in: 0Fixed in: 0.0.0-20200220183623-bac4c82f6975
Fixgo get golang.org/x/crypto@v0.0.0-20200220183623-bac4c82f6975

References