CVE-2022-28327
20.04.2022, 10:15
The generic P-256 feature in crypto/elliptic in Go before 1.17.9 and 1.18.x before 1.18.1 allows a panic via long scalar input.Enginsight
| Vendor | Product | Version |
|---|---|---|
| golang | go | 𝑥 < 1.17.9 |
| golang | go | 1.18.0 ≤ 𝑥 < 1.18.1 |
| fedoraproject | extra_packages_for_enterprise_linux | 7.0 |
| fedoraproject | extra_packages_for_enterprise_linux | 8.0 |
𝑥
= Vulnerable software versions
Ubuntu Releases
Ubuntu Product | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| golang-1.17 |
| ||||||||||||||||||
| golang-1.18 |
|
References