CVE-2019-6486: High severity Golang Go vulnerability
Go before 1.10.8 and 1.11.x before 1.11.5 mishandles P-521 and P-384 elliptic curves, which allows attackers to cause a denial of service (CPU consumption) or possibly conduct ECDH private key recovery attacks.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/golang-1.11to a version that resolves this vulnerability.Fixed in 1.11.6-1+deb10u4Fixed in 1.11.6-1+deb10u7
Event History
Frequently Asked Questions
What is the severity of CVE-2019-6486?
CVE-2019-6486 has a severity level that could lead to denial of service and potentially allow ECDH private key recovery attacks.
How do I fix CVE-2019-6486?
To fix CVE-2019-6486, upgrade to Go version 1.11.6-1+deb10u4 or 1.11.6-1+deb10u7.
What versions of Go are affected by CVE-2019-6486?
CVE-2019-6486 affects Go versions before 1.10.8 and 1.11.x versions prior to 1.11.5.
Which operating systems are impacted by CVE-2019-6486?
CVE-2019-6486 impacts Debian Linux versions 8.0 and 9.0, as well as OpenSUSE Leap version 15.0.
What types of attacks can CVE-2019-6486 enable?
CVE-2019-6486 can enable attacks that lead to denial of service through high CPU consumption and possible ECDH private key recovery.