Clients can cause a panic in SSH servers. An attacker can craft an authentication request message for the “gssapi-with-mic” method which will cause NewServerConn to panic via a nil pointer dereference if ServerConfig.GSSAPIWithMICConfig is nil.
{
"url": "https://pkg.go.dev/vuln/GO-2021-0227",
"review_status": "REVIEWED"
}