Go before 1.10.8 and 1.11.x before 1.11.5 mishandles P-521 and P-384 elliptic curves, which allows attackers to cause a denial of service (CPU consumption) or possibly conduct ECDH private key recovery attacks.
References
Configurations
History
No history.
Information
Published : 2019-01-24 05:29
Updated : 2024-11-21 04:46
NVD link : CVE-2019-6486
Mitre link : CVE-2019-6486
CVE.ORG link : CVE-2019-6486
JSON object : View
Products Affected
golang
- go
debian
- debian_linux
opensuse
- leap
CWE
CWE-770
Allocation of Resources Without Limits or Throttling