First published: Wed Dec 16 2020(Updated: )
A nil pointer dereference in the golang.org/x/crypto/ssh component through v0.0.0-20201203163018-be400aefbc4c for Go allows remote attackers to cause a denial of service against SSH servers.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
go/golang.org/x/crypto | <0.0.0-20201216223049-8b5274cf687f | 0.0.0-20201216223049-8b5274cf687f |
Golang Ssh | <=0.0.0-20201203163018-be400aefbc4c | |
redhat/golang.org/x/crypto v0.0.0-20201216223049 | <8 | 8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
CVE-2020-29652 is a null pointer dereference vulnerability in the golang.org/x/crypto/ssh component.
CVE-2020-29652 can allow an attacker to craft an ssh client connection using the `gssapi-with-mic` authentication method and cause the server to panic.
Versions up to 0.0.0-20201216223049 of the golang.org/x/crypto package are affected.
The severity of CVE-2020-29652 is high, with a score of 7.5.
To fix CVE-2020-29652, update the golang.org/x/crypto package to version 0.0.0-20201216223049 or later.