[FREEBSD:C365536D-E3CF-11EB-9D8D-B37B683944C2] go -- crypto/tls: clients can panic when provided a certificate of the wrong type for the negotiated parameters
Severity
Medium
Affected Packages
1
CVEs
1
The Go project reports:
crypto/tls clients can panic when provided a certificate of
the wrong type for the negotiated parameters. net/http clients
performing HTTPS requests are also affected. The panic can be
triggered by an attacker in a privileged network position
without access to the server certificate's private key, as
long as a trusted ECDSA or Ed25519 certificate for the server
exists (or can be issued), or the client is configured with
Config.InsecureSkipVerify. Clients that disable all TLS_RSA
cipher suites (that is, TLS 1.0–1.2 cipher suites without
ECDHE), as well as TLS 1.3-only clients, are unaffected.
Package | Affected Version |
---|---|
pkg:freebsd/go | < 1.16.6,1 |
- ID
- FREEBSD:C365536D-E3CF-11EB-9D8D-B37B683944C2
- Severity
- medium
- Severity from
- CVE-2021-34558
- URL
- http://vuxml.freebsd.org/freebsd/c365536d-e3cf-11eb-9d8d-b37b683944c2.html
- Published
-
2021-07-07T00:00:00
(3 years ago) - Modified
-
2021-07-12T00:00:00
(3 years ago) - Rights
- FreeBSD VuXML Security Team
- Other Advisories
-
- ALAS-2021-1527
- ALAS2-2021-1694
- ALPINE:CVE-2021-34558
- ALSA-2021:3076
- ALSA-2021:4226
- ALSA-2022:7954
- ASA-202107-42
- ELSA-2021-3076
- ELSA-2021-4226
- ELSA-2022-7954
- ELSA-2024-2988
- FEDORA-2021-07e4d20196
- FEDORA-2021-1bfb61f77c
- FEDORA-2021-25c0011e78
- FEDORA-2021-3a55403080
- FEDORA-2021-47d259d3cf
- FEDORA-2021-54f88bebd4
- FEDORA-2021-6ac9b98f9e
- FEDORA-2021-c35235c250
- FEDORA-2021-ffa749f7f7
- GLSA-202208-02
- GO-2021-0243
- MS:CVE-2021-34558
- openSUSE-SU-2021:1078-1
- openSUSE-SU-2021:1079-1
- openSUSE-SU-2021:2392-1
- openSUSE-SU-2021:2398-1
- RHSA-2021:3076
- RHSA-2021:4226
- RHSA-2022:7954
- RHSA-2024:2988
- SUSE-SU-2021:2392-1
- SUSE-SU-2021:2398-1
Source | # ID | Name | URL |
---|---|---|---|
FreeBSD VuXML | https://github.com/golang/go/issues/47143 |
Type | Package URL | Namespace | Name / Product | Version | Distribution / Platform | Arch | Patch / Fix |
---|---|---|---|---|---|---|---|
Affected | pkg:freebsd/go | go | < 1.16.6,1 |
# CVE | Description | CVSS | EPSS | EPSS Trend (30 days) | Affected Products | Weaknesses | Security Advisories | Exploits | PoC | Pubblication Date | Modification Date |
---|---|---|---|---|---|---|---|---|---|---|---|
# CVE | Description | CVSS | EPSS | EPSS Trend (30 days) | Affected Products | Weaknesses | Security Advisories | PoC | Pubblication Date | Modification Date |