First published: Wed Feb 19 2020(Updated: )
A denial of service vulnerability was found in the SSH package of the golang.org/x/crypto library. An attacker could exploit this flaw by supplying crafted SSH ed25519 keys to cause a crash in applications that use this package as either an SSH client or server.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/golang.org/x/crypto 0.0.0 | <20200220183623 | 20200220183623 |
redhat/kiali | <0:v1.12.10.redhat2-1.el7 | 0:v1.12.10.redhat2-1.el7 |
redhat/ior | <0:1.1.6-1.el8 | 0:1.1.6-1.el8 |
redhat/servicemesh | <0:1.1.6-1.el8 | 0:1.1.6-1.el8 |
redhat/servicemesh-cni | <0:1.1.6-1.el8 | 0:1.1.6-1.el8 |
redhat/servicemesh-grafana | <0:6.4.3-13.el8 | 0:6.4.3-13.el8 |
redhat/servicemesh-operator | <0:1.1.6-2.el8 | 0:1.1.6-2.el8 |
redhat/servicemesh-prometheus | <0:2.14.0-14.el8 | 0:2.14.0-14.el8 |
redhat/jenkins-agent-maven | <35-rhel7 | 35-rhel7 |
redhat/openshift-clients | <0:4.3.31-202007250052.p0.git.3329.59998b9.el7 | 0:4.3.31-202007250052.p0.git.3329.59998b9.el7 |
redhat/openshift | <0:4.5.0-202007012112.p0.git.0.582d7fc.el8 | 0:4.5.0-202007012112.p0.git.0.582d7fc.el8 |
Golang Package Ssh | =0.0.0-20200220183623-bac4c82f6975 | |
Debian Debian Linux | =9.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)