#VU69447 Reachable Assertion in crypto - CVE-2020-9283
Published: November 21, 2022
Vulnerability identifier: #VU69447
Vulnerability risk: Medium
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/U:Green
CVE-ID: CVE-2020-9283
CWE-ID: CWE-617
Exploitation vector: Remote access
Exploit availability:
Public exploit is available
Vulnerable software:
crypto
crypto
Software vendor:
Google
Description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a reachable assertion during signature verification process. A remote attacker can supply a specially crafted certificate to the application (server or client) and perform a denial of service (DoS) attack.
Remediation
Install updates from vendor's website.
External links
- https://groups.google.com/forum/#!topic/golang-announce/3L45YRc91SY
- http://packetstormsecurity.com/files/156480/Go-SSH-0.0.2-Denial-Of-Service.html
- https://lists.debian.org/debian-lts-announce/2020/10/msg00014.html
- https://lists.debian.org/debian-lts-announce/2020/11/msg00027.html
- https://lists.debian.org/debian-lts-announce/2020/11/msg00031.html
- https://packetstormsecurity.com/files/156480/Go-SSH-0.0.2-Denial-Of-Service.html