CVE-2020-7919

high
New! CVE Severity Now Using CVSS v3

The calculated severity for CVEs has been updated to use CVSS v3 by default. CVEs that do not have a CVSS v3 score will fall back CVSS v2 for calculating severity. Severity display preferences can be toggled in the settings dropdown.

Description

Go before 1.12.16 and 1.13.x before 1.13.7 (and the crypto/cryptobyte package before 0.0.0-20200124225646-8b5121be2f68 for Go) allows attacks on clients (resulting in a panic) via a malformed X.509 certificate.

References

https://groups.google.com/forum/#!topic/golang-announce/Hsw4mHYc470

https://groups.google.com/forum/#!topic/golang-announce/-sdUB4VEQkA

https://groups.google.com/forum/#!forum/golang-announce

https://security.netapp.com/advisory/ntap-20200327-0001/

https://lists.fedoraproject.org/archives/list/[email protected]/message/S43VLYRURELDWX4D5RFOYBNFGO6CGBBC/

https://www.debian.org/security/2021/dsa-4848

https://www.oracle.com/security-alerts/cpuApr2021.html

Details

Source: MITRE

Published: 2020-03-16

Updated: 2021-06-14

Type: CWE-295

Risk Information

CVSS v2

Base Score: 7.8

Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C

Impact Score: 6.9

Exploitability Score: 10

Severity: HIGH

CVSS v3

Base Score: 7.5

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Impact Score: 3.6

Exploitability Score: 3.9

Severity: HIGH

Tenable Plugins

View all (6 total)

IDNameProductFamilySeverity
146371Debian DSA-4848-1 : golang-1.11 - security updateNessusDebian Local Security Checks
medium
139134EulerOS 2.0 SP8 : golang (EulerOS-SA-2020-1804)NessusHuawei Local Security Checks
high
136575Photon OS 3.0: Go PHSA-2020-3.0-0087NessusPhotonOS Local Security Checks
high
136553Photon OS 1.0: Go PHSA-2020-1.0-0292NessusPhotonOS Local Security Checks
high
136327Photon OS 2.0: Go PHSA-2020-2.0-0238NessusPhotonOS Local Security Checks
high
135369Fedora 31 : golang (2020-12bc5b5597)NessusFedora Local Security Checks
high