Back

HIGH

golang: crypto/x509 allows for denial of service via crafted TLS client certificate

Published Dec 14, 2018

Description

The crypto/x509 package of Go before 1.10.6 and 1.11.x before 1.11.3 does not limit the amount of work performed for each chain verification, which might allow attackers to craft pathological inputs leading to a CPU denial of service. Go TLS servers accepting client certificates and TLS clients are affected.

Affected products

Remediation

Red Hat statement

This issue affects the version of golang package in Red Hat Enterprise Linux 7. The golang package, previously available in the Optional channel, will no longer receive updates in Red Hat Enterprise Linux 7. Developers are encouraged to use the Go Toolset instead, which is available through the Red Hat Developer program. https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/7/html/7.6_release_notes/chap-red_hat_enterprise_linux-7.6_release_notes-deprecated_functionality_in_rhel7#idm139716309923696

Metrics

References (15)

Change history (6)
  1. MITRE
    • CVSS severity changed from HIGH to MEDIUM
    • CVSS vector changed from CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H to CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
    • CVSS score changed from 7.5 to 5.9
  2. REDHAT
    • CVSS severity changed from MEDIUM to HIGH
    • CVSS vector changed from CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H to CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
    • CVSS score changed from 5.9 to 7.5
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Dec 14, 2018
Updated Aug 5, 2024
Reserved Sep 11, 2018
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Dec 13, 2018