CVE-2019-17596

Source
https://nvd.nist.gov/vuln/detail/CVE-2019-17596
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-17596.json
Aliases
Related
Published
2019-10-24T22:15:10Z
Modified
2023-11-29T07:19:12.956660Z
Details

Go before 1.12.11 and 1.3.x before 1.13.2 can panic upon an attempt to process network traffic containing an invalid DSA public key. There are several attack scenarios, such as traffic from a client to a server that verifies client certificates.

References

Affected packages

Git / github.com/golang/go

Affected ranges

Affected versions

go1.*

go1.13
go1.13.1