[GO-2024-2660] Memory leak in github.com/golang-fips/openssl/v2 and github.com/microsoft/go-crypto-openssl

Severity High
Affected Packages 2
Fixed Packages 2
CVEs 1

Using crafted public RSA keys can cause a small memory leak when encrypting and
verifying payloads. This can be gradually leveraged into a denial of service
attack.

Source # ID Name URL
Security Advisory https://github.com/advisories/GHSA-78hx-gp6g-7mj6
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Fixed pkg:golang/github.com/microsoft/go-crypto-openssl/openssl github.com/microsoft/go-crypto-openssl openssl = 0.2.9
Affected pkg:golang/github.com/microsoft/go-crypto-openssl/openssl github.com/microsoft/go-crypto-openssl openssl >= 0.2.8 < 0.2.9
Fixed pkg:golang/github.com/golang-fips/openssl/v2 github.com/golang-fips/openssl v2 = 2.0.1
Affected pkg:golang/github.com/golang-fips/openssl/v2 github.com/golang-fips/openssl v2 >= 2.0.0 < 2.0.1
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...