#VU64805 Input validation error


Published: 2022-06-29

Vulnerability identifier: #VU64805

Vulnerability risk: Medium

CVSSv3.1:

CVE-ID: CVE-2021-43565

CWE-ID: CWE-20

Exploitation vector: Network

Exploit availability: No

Vulnerable software:
crypto
Universal components / Libraries / Libraries used by multiple products

Vendor: Go

Description

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to insufficient validation of user-supplied input when parsing a Signer to ServerConfig.AddHostKey in cases where the Signer passed to AddHostKey does not implement AlgorithmSigner or the Signer passed to AddHostKey returns a key of type “ssh-rsa” from its PublicKey method. A remote attacker can pass specially crafted input to the application and perform a denial of service (DoS) attack.

Mitigation
Install updates from vendor's website.

Vulnerable software versions

crypto: 0.0.0-20220314234659-1baeb1ce4c0b


CPE

External links
http://pkg.go.dev/vuln/GO-2021-0356


Q & A

Can this vulnerability be exploited remotely?

Is there known malware, which exploits this vulnerability?


Latest bulletins with this vulnerability