CVE Vulnerabilities

CVE-2019-17596

Interpretation Conflict

Published: Oct 24, 2019 | Modified: Nov 21, 2024
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
7.5 MODERATE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Go before 1.12.11 and 1.3.x before 1.13.2 can panic upon an attempt to process network traffic containing an invalid DSA public key. There are several attack scenarios, such as traffic from a client to a server that verifies client certificates.

Weakness

Product A handles inputs or steps differently than Product B, which causes A to perform incorrect actions based on its perception of B’s state.

Affected Software

NameVendorStart VersionEnd Version
GoGolang1.12 (including)1.12.11 (excluding)
GoGolang1.13 (including)1.13.2 (excluding)
Red Hat Developer ToolsRedHatgo-toolset-1.12-0:1.12.12-4.el7*
Red Hat Developer ToolsRedHatgo-toolset-1.12-golang-0:1.12.12-4.el7*
Red Hat Enterprise Linux 8RedHatgo-toolset:rhel8-8010020191220185136.0ed30617*
Red Hat OpenShift Container Platform 4.3RedHatcri-o-0:1.16.2-13.dev.rhaos4.3.gita83f883.el7*
Red Hat OpenShift Container Platform 4.3RedHatopenshift-0:4.3.1-202001310552.git.0.331f390.el8*
Red Hat OpenShift Container Platform 4.3RedHatopenshift-clients-0:4.3.1-202001310552.git.1.075d46a.el7*
GolangUbuntutrusty*
Golang-1.10Ubuntubionic*
Golang-1.10Ubuntudisco*
Golang-1.10Ubuntuesm-infra/bionic*
Golang-1.10Ubuntutrusty*
Golang-1.10Ubuntutrusty/esm*
Golang-1.10Ubuntuxenial*
Golang-1.11Ubuntudisco*
Golang-1.12Ubuntudisco*
Golang-1.12Ubuntueoan*
Golang-1.13Ubuntubionic*
Golang-1.13Ubuntueoan*
Golang-1.13Ubuntuesm-apps/bionic*
Golang-1.13Ubuntuesm-apps/jammy*
Golang-1.13Ubuntuesm-apps/xenial*
Golang-1.13Ubuntuesm-infra/focal*
Golang-1.13Ubuntufocal*
Golang-1.13Ubuntugroovy*
Golang-1.13Ubuntuhirsute*
Golang-1.13Ubuntuimpish*
Golang-1.13Ubuntujammy*
Golang-1.13Ubuntukinetic*
Golang-1.13Ubuntutrusty*
Golang-1.13Ubuntuupstream*
Golang-1.13Ubuntuxenial*
Golang-1.6Ubuntutrusty*
Golang-1.6Ubuntuxenial*
Golang-1.8Ubuntubionic*
Golang-1.8Ubuntuesm-apps/bionic*
Golang-1.9Ubuntubionic*
Golang-1.9Ubuntuesm-apps/bionic*

References