CVE-2021-34558
15.07.2021, 14:15
The crypto/tls package of Go through 1.16.5 does not properly assert that the type of public key in an X.509 certificate matches the expected type when doing a RSA based key exchange, allowing a malicious TLS server to cause a TLS client to panic.Enginsight
Vendor | Product | Version |
---|---|---|
golang | go | 𝑥 < 1.15.14 |
golang | go | 1.16.0 ≤ 𝑥 < 1.16.6 |
netapp | cloud_insights_telegraf | - |
netapp | storagegrid | - |
netapp | trident | - |
oracle | timesten_in-memory_database | 𝑥 < 21.1.1.1.0 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
golang |
| ||||||||||||||||||||||||
golang-1.10 |
| ||||||||||||||||||||||||
golang-1.13 |
| ||||||||||||||||||||||||
golang-1.14 |
| ||||||||||||||||||||||||
golang-1.15 |
| ||||||||||||||||||||||||
golang-1.16 |
| ||||||||||||||||||||||||
golang-1.6 |
| ||||||||||||||||||||||||
golang-1.8 |
| ||||||||||||||||||||||||
golang-1.9 |
|
Common Weakness Enumeration
References