Improper Certificate Validation in Go programming language - CVE-2020-7919

 

Improper Certificate Validation in Go programming language - CVE-2020-7919

Published: March 16, 2020 / Updated: July 13, 2020


Vulnerability identifier: #VU29673
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-7919
CWE-ID: CWE-295
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to perform a denial of service (DoS) attack.

Go before 1.12.16 and 1.13.x before 1.13.7 (and the crypto/cryptobyte package before 0.0.0-20200124225646-8b5121be2f68 for Go) allows attacks on clients (resulting in a panic) via a malformed X.509 certificate.


Affected software

Go programming language
apk-file (Alpine package)
alertmanager (Alpine package)
golang-1.11 (Debian package)
go (Alpine package)
golang
ObjectScale
IBM Watson Machine Learning Accelerator
IBM Cloud Pak for Watson AIOps
IBM Cloud Automation Manager
IBM Robotic Process Automation
Netcool Operations Insight
Fedora
IBM CICS TX Standard
IBM CICS TX Advanced

How to mitigate CVE-2020-7919

Install update from vendor's website.

Go programming language - update to 1.13.7
apk-file (Alpine package) - update to 0.3.6-r1
alertmanager (Alpine package) - update to 0.20.0-r2
ObjectScale - update to 1.3.0
golang-1.11 (Debian package) - update to 1.11.6-1+deb10u4
go (Alpine package) - addressed in versions 1.13.8-r0, 1.13.10-r0
IBM Robotic Process Automation - update to 21.0.3.1
Netcool Operations Insight - update to 1.6.6
golang - addressed in versions 1.13.9-1.fc31, 1.13.11-1.el6, 1.13.11-1.el7
IBM Watson Machine Learning Accelerator - update to 2.3.9
IBM Cloud Pak for Watson AIOps - update to 4.1
IBM CICS TX Standard - update to 11.1.0.0 ifix5
IBM CICS TX Advanced - update to 11.1.0.0 ifix5

External References

Related Security Bulletins