VDB
Sign up
HIGH7.5

GHSA-3vm4-22fp-5rfm

golang.org/x/crypto/ssh NULL Pointer Dereference vulnerability

Quick fix

GHSA-3vm4-22fp-5rfm — golang.org/x/crypto: upgrade to the fixed version with the command below.

go get golang.org/x/crypto@v0.0.0-20201216223049-8b5274cf687f

Details

A nil pointer dereference in the golang.org/x/crypto/ssh component through v0.0.0-20201203163018-be400aefbc4c for Go allows remote attackers to cause a denial of service against SSH servers. An attacker can craft an authentication request message for the `gssapi-with-mic` method which will cause NewServerConn to panic via a nil pointer dereference if ServerConfig.GSSAPIWithMICConfig is nil.

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/golang.org/x/crypto
Introduced in: 0Fixed in: 0.0.0-20201216223049-8b5274cf687f
Fixgo get golang.org/x/crypto@v0.0.0-20201216223049-8b5274cf687f

References