Improper Certificate Validation in Go programming language - CVE-2020-7919
Published: March 16, 2020 / Updated: July 13, 2020
Vulnerability details
The vulnerability allows a remote non-authenticated attacker to perform a denial of service (DoS) attack.
Go before 1.12.16 and 1.13.x before 1.13.7 (and the crypto/cryptobyte package before 0.0.0-20200124225646-8b5121be2f68 for Go) allows attacks on clients (resulting in a panic) via a malformed X.509 certificate.
Affected software
apk-file (Alpine package)
alertmanager (Alpine package)
golang-1.11 (Debian package)
go (Alpine package)
golang
ObjectScale
IBM Watson Machine Learning Accelerator
IBM Cloud Pak for Watson AIOps
IBM Cloud Automation Manager
IBM Robotic Process Automation
Netcool Operations Insight
Fedora
IBM CICS TX Standard
IBM CICS TX Advanced
How to mitigate CVE-2020-7919
apk-file (Alpine package) - update to 0.3.6-r1
alertmanager (Alpine package) - update to 0.20.0-r2
ObjectScale - update to 1.3.0
golang-1.11 (Debian package) - update to 1.11.6-1+deb10u4
go (Alpine package) - addressed in versions 1.13.8-r0, 1.13.10-r0
IBM Robotic Process Automation - update to 21.0.3.1
Netcool Operations Insight - update to 1.6.6
golang - addressed in versions 1.13.9-1.fc31, 1.13.11-1.el6, 1.13.11-1.el7
IBM Watson Machine Learning Accelerator - update to 2.3.9
IBM Cloud Pak for Watson AIOps - update to 4.1
IBM CICS TX Standard - update to 11.1.0.0 ifix5
IBM CICS TX Advanced - update to 11.1.0.0 ifix5
External References
- https://groups.google.com/forum/#!forum/golang-announce
- https://groups.google.com/forum/#!topic/golang-announce/Hsw4mHYc470
- https://groups.google.com/forum/#!topic/golang-announce/-sdUB4VEQkA
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/S43VLYRURELDWX4D5RFOYBNFGO6CGBBC/
- https://security.netapp.com/advisory/ntap-20200327-0001/
Related Security Bulletins
- Improper Certificate Validation in GOland Go fro del
- Improper Certificate Validation in go (Alpine package)
- Improper Certificate Validation in apk-file (Alpine package)
- Improper Certificate Validation in 6cord (Alpine package)
- Improper Certificate Validation in alertmanager (Alpine package)
- Improper Certificate Validation in containerd (Alpine package)
- Debian update for golang-1.11
- Multiple vulnerabilities in IBM Robotic Process Automation for Cloud Pak
- Multiple vulnerabilities in Netcool Operations Insight
- Multiple vulnerabilities in IBM CICS TX Standard
- Multiple vulnerabilities in IBM CICS TX Advanced
- Improper Certificate Validation in IBM Cloud Automation Manager
- Multiple vulnerabilities in IBM Cloud Pak for Watson AIOps
- Multiple vulnerabilities in IBM Watson Machine Learning Accelerator on Cloud Pak for Data
- Fedora 31 update for golang
- Fedora EPEL 7 update for golang
- Fedora EPEL 6 update for golang
- Multiple vulnerabilities in Dell ObjectScale