Back

HIGH

golang: Integer overflow on 32bit architectures via crafted certificate allows for denial of service

Published Mar 16, 2020

Description

Go before 1.12.16 and 1.13.x before 1.13.7 (and the crypto/cryptobyte package before 0.0.0-20200124225646-8b5121be2f68 for Go) allows attacks on clients (resulting in a panic) via a malformed X.509 certificate.

Affected products

Remediation

Red Hat statement

Below products are only supported on 64bit architectures and are therefore not affected by this flaw: * OpenShift Container Platform * OpenShift Service Mesh * Red Hat Ceph Storage * Red Hat Gluster Storage * Container-native Virtualization

References (24)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner mitre
Published Mar 16, 2020
Updated Aug 4, 2024
Reserved Jan 23, 2020

CISA Vulnrichment

No data

NVD

Status Modified
Modified Jun 17, 2026

Red Hat

Severity Important
Public date Jan 28, 2020
Bugzilla 1808041

ENISA EUVD

Assigner mitre
Published Mar 16, 2020
Updated Aug 4, 2024