CVE-2021-34558
15.07.2021, 14:15
The crypto/tls package of Go through 1.16.5 does not properly assert that the type of public key in an X.509 certificate matches the expected type when doing a RSA based key exchange, allowing a malicious TLS server to cause a TLS client to panic.Enginsight
| Vendor | Product | Version |
|---|---|---|
| golang | go | 𝑥 < 1.15.14 |
| golang | go | 1.16.0 ≤ 𝑥 < 1.16.6 |
| netapp | cloud_insights_telegraf | - |
| netapp | storagegrid | - |
| netapp | trident | - |
| oracle | timesten_in-memory_database | 𝑥 < 21.1.1.1.0 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| golang |
| ||||||||||||||||||||||||
| golang-1.10 |
| ||||||||||||||||||||||||
| golang-1.13 |
| ||||||||||||||||||||||||
| golang-1.14 |
| ||||||||||||||||||||||||
| golang-1.15 |
| ||||||||||||||||||||||||
| golang-1.16 |
| ||||||||||||||||||||||||
| golang-1.6 |
| ||||||||||||||||||||||||
| golang-1.8 |
| ||||||||||||||||||||||||
| golang-1.9 |
|
Common Weakness Enumeration
References