[GO-2023-2044] Panic when processing post-handshake message on QUIC connections in crypto/tls
Severity
High
Affected Packages
1
Fixed Packages
1
CVEs
1
Processing an incomplete post-handshake message for a QUIC connection can cause
a panic.
Package | Affected Version |
---|---|
pkg:golang/crypto/tls | >= 1.21.0, < 1.21.1 |
Package | Fixed Version |
---|---|
pkg:golang/crypto/tls | = 1.21.1 |
- ID
- GO-2023-2044
- Severity
- high
- Severity from
- CVE-2023-39321
- URL
- https://pkg.go.dev/vuln/GO-2023-2044
- Published
-
2023-09-06T22:21:26
(12 months ago) - Modified
-
2024-07-17T19:54:18
(2 months ago) - Other Advisories
-
- ALPINE:CVE-2023-39321
- ALSA-2023:7762
- ALSA-2023:7763
- ALSA-2023:7764
- ALSA-2023:7765
- ALSA-2023:7766
- ALSA-2024:0121
- ELSA-2023-7762
- ELSA-2023-7763
- ELSA-2023-7764
- ELSA-2023-7766
- ELSA-2024-0121
- ELSA-2024-2988
- FREEBSD:BEB36F39-4D74-11EE-985E-BFF341E78D94
- GLSA-202311-09
- openSUSE-SU-2023:0360-1
- RHBA-2023:6364
- RHBA-2023:6928
- RHSA-2023:7762
- RHSA-2023:7763
- RHSA-2023:7764
- RHSA-2023:7765
- RHSA-2023:7766
- RHSA-2024:0121
- RHSA-2024:2988
- SUSE-SU-2023:3701-1
- SUSE-SU-2023:4469-1
# CVE | Description | CVSS | EPSS | EPSS Trend (30 days) | Affected Products | Weaknesses | Security Advisories | Exploits | PoC | Pubblication Date | Modification Date |
---|---|---|---|---|---|---|---|---|---|---|---|
# CVE | Description | CVSS | EPSS | EPSS Trend (30 days) | Affected Products | Weaknesses | Security Advisories | PoC | Pubblication Date | Modification Date |