CVE Vulnerabilities

CVE-2019-17596

Interpretation Conflict

Published: Oct 24, 2019 | Modified: Nov 07, 2023
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
7.5 MODERATE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Ubuntu
MEDIUM

Go before 1.12.11 and 1.3.x before 1.13.2 can panic upon an attempt to process network traffic containing an invalid DSA public key. There are several attack scenarios, such as traffic from a client to a server that verifies client certificates.

Weakness

Product A handles inputs or steps differently than Product B, which causes A to perform incorrect actions based on its perception of B’s state.

Affected Software

Name Vendor Start Version End Version
Go Golang 1.12 (including) 1.12.11 (excluding)
Go Golang 1.13 (including) 1.13.2 (excluding)
Red Hat Developer Tools RedHat go-toolset-1.12-0:1.12.12-4.el7 *
Red Hat Developer Tools RedHat go-toolset-1.12-golang-0:1.12.12-4.el7 *
Red Hat Enterprise Linux 8 RedHat go-toolset:rhel8-8010020191220185136.0ed30617 *
Red Hat OpenShift Container Platform 4.3 RedHat cri-o-0:1.16.2-13.dev.rhaos4.3.gita83f883.el7 *
Red Hat OpenShift Container Platform 4.3 RedHat openshift-0:4.3.1-202001310552.git.0.331f390.el8 *
Red Hat OpenShift Container Platform 4.3 RedHat openshift-clients-0:4.3.1-202001310552.git.1.075d46a.el8 *
Golang Ubuntu trusty *
Golang-1.10 Ubuntu bionic *
Golang-1.10 Ubuntu disco *
Golang-1.10 Ubuntu esm-infra/bionic *
Golang-1.10 Ubuntu trusty *
Golang-1.10 Ubuntu trusty/esm *
Golang-1.10 Ubuntu xenial *
Golang-1.11 Ubuntu disco *
Golang-1.12 Ubuntu disco *
Golang-1.12 Ubuntu eoan *
Golang-1.13 Ubuntu bionic *
Golang-1.13 Ubuntu eoan *
Golang-1.13 Ubuntu focal *
Golang-1.13 Ubuntu groovy *
Golang-1.13 Ubuntu hirsute *
Golang-1.13 Ubuntu impish *
Golang-1.13 Ubuntu jammy *
Golang-1.13 Ubuntu kinetic *
Golang-1.13 Ubuntu trusty *
Golang-1.13 Ubuntu upstream *
Golang-1.13 Ubuntu xenial *
Golang-1.6 Ubuntu trusty *
Golang-1.6 Ubuntu xenial *
Golang-1.8 Ubuntu bionic *
Golang-1.8 Ubuntu esm-apps/bionic *
Golang-1.9 Ubuntu bionic *
Golang-1.9 Ubuntu esm-apps/bionic *

References