golang.org/x/crypto before v0.0.0-20200220183623-bac4c82f6975 for Go allows a panic during signature verification in the golang.org/x/crypto/ssh package. A client can attack an SSH server that accepts public keys. Also, a server can attack any SSH client.
Metrics
No CVSS v4.0
Attack Vector Network
Attack Complexity Low
Privileges Required None
Scope Unchanged
Confidentiality Impact None
Integrity Impact None
Availability Impact High
User Interaction None
No CVSS v3.0
Access Vector Network
Access Complexity Low
Authentication None
Confidentiality Impact None
Integrity Impact None
Availability Impact Partial
AV:N/AC:L/Au:N/C:N/I:N/A:P
This CVE is not in the KEV list.
Key SSVC decision points have not yet been added.
Affected Vendors & Products
Vendors | Products |
---|---|
Debian |
|
Golang |
|
Redhat |
|
Configuration 1 [-]
|
Configuration 2 [-]
|
Package | CPE | Advisory | Released Date |
---|---|---|---|
3scale API Management 2.10 on RHEL 7 | |||
3scale-amp2/3scale-rhel7-operator:1.13.0-17 | cpe:/a:redhat:3scale_amp:2.10::el7 | RHSA-2021:1129 | 2021-04-08T00:00:00Z |
3scale-amp2/3scale-rhel7-operator-metadata:2.10.0-38 | cpe:/a:redhat:3scale_amp:2.10::el7 | RHSA-2021:1129 | 2021-04-08T00:00:00Z |
3scale-amp2/apicast-rhel7-operator:1.13.0-4 | cpe:/a:redhat:3scale_amp:2.10::el7 | RHSA-2021:1129 | 2021-04-08T00:00:00Z |
3scale-amp2/apicast-rhel7-operator-metadata:2.10.0-9 | cpe:/a:redhat:3scale_amp:2.10::el7 | RHSA-2021:1129 | 2021-04-08T00:00:00Z |
Jaeger-1.17 | |||
distributed-tracing/jaeger-agent-rhel7:1.17.6-1 | cpe:/a:redhat:jaeger:1.17::el7 | RHSA-2020:3370 | 2020-08-06T00:00:00Z |
distributed-tracing/jaeger-all-in-one-rhel7:1.17.6-1 | cpe:/a:redhat:jaeger:1.17::el7 | RHSA-2020:3370 | 2020-08-06T00:00:00Z |
distributed-tracing/jaeger-collector-rhel7:1.17.6-1 | cpe:/a:redhat:jaeger:1.17::el7 | RHSA-2020:3370 | 2020-08-06T00:00:00Z |
distributed-tracing/jaeger-es-index-cleaner-rhel7:1.17.6-1 | cpe:/a:redhat:jaeger:1.17::el7 | RHSA-2020:3370 | 2020-08-06T00:00:00Z |
distributed-tracing/jaeger-es-rollover-rhel7:1.17.6-1 | cpe:/a:redhat:jaeger:1.17::el7 | RHSA-2020:3370 | 2020-08-06T00:00:00Z |
distributed-tracing/jaeger-ingester-rhel7:1.17.6-1 | cpe:/a:redhat:jaeger:1.17::el7 | RHSA-2020:3370 | 2020-08-06T00:00:00Z |
distributed-tracing/jaeger-query-rhel7:1.17.6-1 | cpe:/a:redhat:jaeger:1.17::el7 | RHSA-2020:3370 | 2020-08-06T00:00:00Z |
distributed-tracing/jaeger-rhel7-operator:1.17.6-1 | cpe:/a:redhat:jaeger:1.17::el7 | RHSA-2020:3370 | 2020-08-06T00:00:00Z |
OpenShift Service Mesh 1.0 | |||
openshift-service-mesh/3scale-istio-adapter-rhel8:1.0.0-8 | cpe:/a:redhat:service_mesh:1.0::el8 | RHSA-2020:3372 | 2020-08-06T00:00:00Z |
Openshift Service Mesh 1.1 | |||
kiali-0:v1.12.10.redhat2-1.el7 | cpe:/a:redhat:service_mesh:1.1::el7 | RHSA-2020:3369 | 2020-08-06T00:00:00Z |
OpenShift Service Mesh 1.1 | |||
ior-0:1.1.6-1.el8 | cpe:/a:redhat:service_mesh:1.1::el8 | RHSA-2020:3369 | 2020-08-06T00:00:00Z |
servicemesh-0:1.1.6-1.el8 | cpe:/a:redhat:service_mesh:1.1::el8 | RHSA-2020:3369 | 2020-08-06T00:00:00Z |
servicemesh-cni-0:1.1.6-1.el8 | cpe:/a:redhat:service_mesh:1.1::el8 | RHSA-2020:3369 | 2020-08-06T00:00:00Z |
servicemesh-grafana-0:6.4.3-13.el8 | cpe:/a:redhat:service_mesh:1.1::el8 | RHSA-2020:3369 | 2020-08-06T00:00:00Z |
servicemesh-operator-0:1.1.6-2.el8 | cpe:/a:redhat:service_mesh:1.1::el8 | RHSA-2020:3369 | 2020-08-06T00:00:00Z |
servicemesh-prometheus-0:2.14.0-14.el8 | cpe:/a:redhat:service_mesh:1.1::el8 | RHSA-2020:3369 | 2020-08-06T00:00:00Z |
Red Hat OpenShift Container Platform 4 | |||
atomic-openshift-cluster-autoscaler-container | cpe:/a:redhat:openshift:4.3::el7 | RHSA-2020:4264 | 2020-10-20T00:00:00Z |
baremetal-machine-controller-container | cpe:/a:redhat:openshift:4.3::el7 | RHSA-2020:4264 | 2020-10-20T00:00:00Z |
cluster-monitoring-operator-container | cpe:/a:redhat:openshift:4.3::el7 | RHSA-2020:4264 | 2020-10-20T00:00:00Z |
cluster-network-operator-container | cpe:/a:redhat:openshift:4.3::el7 | RHSA-2020:4264 | 2020-10-20T00:00:00Z |
cluster-node-tuning-operator-container | cpe:/a:redhat:openshift:4.3::el7 | RHSA-2020:4264 | 2020-10-20T00:00:00Z |
cluster-version-operator-container | cpe:/a:redhat:openshift:4.3::el7 | RHSA-2020:4264 | 2020-10-20T00:00:00Z |
configmap-reload-container | cpe:/a:redhat:openshift:4.3::el7 | RHSA-2020:4264 | 2020-10-20T00:00:00Z |
coredns-container | cpe:/a:redhat:openshift:4.3::el7 | RHSA-2020:4264 | 2020-10-20T00:00:00Z |
golang-github-openshift-oauth-proxy-container | cpe:/a:redhat:openshift:4.3::el7 | RHSA-2020:4264 | 2020-10-20T00:00:00Z |
golang-github-prometheus-alertmanager-container | cpe:/a:redhat:openshift:4.3::el7 | RHSA-2020:4264 | 2020-10-20T00:00:00Z |
golang-github-prometheus-node_exporter-container | cpe:/a:redhat:openshift:4.3::el7 | RHSA-2020:4264 | 2020-10-20T00:00:00Z |
golang-github-prometheus-prometheus-container | cpe:/a:redhat:openshift:4.3::el7 | RHSA-2020:4264 | 2020-10-20T00:00:00Z |
grafana-container | cpe:/a:redhat:openshift:4.3::el7 | RHSA-2020:4264 | 2020-10-20T00:00:00Z |
ironic-container | cpe:/a:redhat:openshift:4.3::el7 | RHSA-2020:4264 | 2020-10-20T00:00:00Z |
ironic-hardware-inventory-recorder-image-container | cpe:/a:redhat:openshift:4.3::el7 | RHSA-2020:4264 | 2020-10-20T00:00:00Z |
ironic-inspector-container | cpe:/a:redhat:openshift:4.3::el7 | RHSA-2020:4264 | 2020-10-20T00:00:00Z |
ironic-ipa-downloader-container | cpe:/a:redhat:openshift:4.3::el7 | RHSA-2020:4264 | 2020-10-20T00:00:00Z |
ironic-rhcos-downloader-container | cpe:/a:redhat:openshift:4.3::el7 | RHSA-2020:4264 | 2020-10-20T00:00:00Z |
ironic-static-ip-manager-container | cpe:/a:redhat:openshift:4.3::el7 | RHSA-2020:4264 | 2020-10-20T00:00:00Z |
jenkins-agent-maven-35-rhel7-container | cpe:/a:redhat:openshift:4.3::el7 | RHSA-2020:4264 | 2020-10-20T00:00:00Z |
kube-proxy-container | cpe:/a:redhat:openshift:4.3::el7 | RHSA-2020:4264 | 2020-10-20T00:00:00Z |
kube-rbac-proxy-container | cpe:/a:redhat:openshift:4.3::el7 | RHSA-2020:4264 | 2020-10-20T00:00:00Z |
kube-state-metrics-container | cpe:/a:redhat:openshift:4.3::el7 | RHSA-2020:4264 | 2020-10-20T00:00:00Z |
kuryr-cni-container | cpe:/a:redhat:openshift:4.3::el7 | RHSA-2020:4264 | 2020-10-20T00:00:00Z |
kuryr-controller-container | cpe:/a:redhat:openshift:4.3::el7 | RHSA-2020:4264 | 2020-10-20T00:00:00Z |
local-storage-static-provisioner-container | cpe:/a:redhat:openshift:4.3::el7 | RHSA-2020:4264 | 2020-10-20T00:00:00Z |
marketplace-operator-container | cpe:/a:redhat:openshift:4.3::el7 | RHSA-2020:4264 | 2020-10-20T00:00:00Z |
multus-cni-container | cpe:/a:redhat:openshift:4.3::el7 | RHSA-2020:4264 | 2020-10-20T00:00:00Z |
openshift-enterprise-builder-container | cpe:/a:redhat:openshift:4.3::el7 | RHSA-2020:4264 | 2020-10-20T00:00:00Z |
openshift-enterprise-cli-container | cpe:/a:redhat:openshift:4.3::el7 | RHSA-2020:4264 | 2020-10-20T00:00:00Z |
openshift-enterprise-console-container | cpe:/a:redhat:openshift:4.3::el7 | RHSA-2020:4264 | 2020-10-20T00:00:00Z |
openshift-enterprise-console-operator-container | cpe:/a:redhat:openshift:4.3::el7 | RHSA-2020:4264 | 2020-10-20T00:00:00Z |
openshift-enterprise-deployer-container | cpe:/a:redhat:openshift:4.3::el7 | RHSA-2020:4264 | 2020-10-20T00:00:00Z |
openshift-enterprise-haproxy-router-container | cpe:/a:redhat:openshift:4.3::el7 | RHSA-2020:4264 | 2020-10-20T00:00:00Z |
openshift-enterprise-hyperkube-container | cpe:/a:redhat:openshift:4.3::el7 | RHSA-2020:4264 | 2020-10-20T00:00:00Z |
openshift-enterprise-keepalived-ipfailover-container | cpe:/a:redhat:openshift:4.3::el7 | RHSA-2020:4264 | 2020-10-20T00:00:00Z |
openshift-enterprise-pod-container | cpe:/a:redhat:openshift:4.3::el7 | RHSA-2020:4264 | 2020-10-20T00:00:00Z |
openshift-enterprise-registry-container | cpe:/a:redhat:openshift:4.3::el7 | RHSA-2020:4264 | 2020-10-20T00:00:00Z |
openshift-enterprise-tests-container | cpe:/a:redhat:openshift:4.3::el7 | RHSA-2020:4264 | 2020-10-20T00:00:00Z |
openshift-jenkins-2-container | cpe:/a:redhat:openshift:4.3::el7 | RHSA-2020:4264 | 2020-10-20T00:00:00Z |
operator-lifecycle-manager-container | cpe:/a:redhat:openshift:4.3::el7 | RHSA-2020:4264 | 2020-10-20T00:00:00Z |
operator-registry-container | cpe:/a:redhat:openshift:4.3::el7 | RHSA-2020:4264 | 2020-10-20T00:00:00Z |
ose-aws-machine-controllers-container | cpe:/a:redhat:openshift:4.3::el7 | RHSA-2020:4264 | 2020-10-20T00:00:00Z |
ose-azure-machine-controllers-container | cpe:/a:redhat:openshift:4.3::el7 | RHSA-2020:4264 | 2020-10-20T00:00:00Z |
ose-cli-artifacts-container | cpe:/a:redhat:openshift:4.3::el7 | RHSA-2020:4264 | 2020-10-20T00:00:00Z |
ose-cloud-credential-operator-container | cpe:/a:redhat:openshift:4.3::el7 | RHSA-2020:4264 | 2020-10-20T00:00:00Z |
ose-cluster-authentication-operator-container | cpe:/a:redhat:openshift:4.3::el7 | RHSA-2020:4264 | 2020-10-20T00:00:00Z |
ose-cluster-autoscaler-operator-container | cpe:/a:redhat:openshift:4.3::el7 | RHSA-2020:4264 | 2020-10-20T00:00:00Z |
ose-cluster-bootstrap-container | cpe:/a:redhat:openshift:4.3::el7 | RHSA-2020:4264 | 2020-10-20T00:00:00Z |
ose-cluster-config-operator-container | cpe:/a:redhat:openshift:4.3::el7 | RHSA-2020:4264 | 2020-10-20T00:00:00Z |
ose-cluster-dns-operator-container | cpe:/a:redhat:openshift:4.3::el7 | RHSA-2020:4264 | 2020-10-20T00:00:00Z |
ose-cluster-image-registry-operator-container | cpe:/a:redhat:openshift:4.3::el7 | RHSA-2020:4264 | 2020-10-20T00:00:00Z |
ose-cluster-ingress-operator-container | cpe:/a:redhat:openshift:4.3::el7 | RHSA-2020:4264 | 2020-10-20T00:00:00Z |
ose-cluster-kube-apiserver-operator-container | cpe:/a:redhat:openshift:4.3::el7 | RHSA-2020:4264 | 2020-10-20T00:00:00Z |
ose-cluster-kube-controller-manager-operator-container | cpe:/a:redhat:openshift:4.3::el7 | RHSA-2020:4264 | 2020-10-20T00:00:00Z |
ose-cluster-kube-scheduler-operator-container | cpe:/a:redhat:openshift:4.3::el7 | RHSA-2020:4264 | 2020-10-20T00:00:00Z |
ose-cluster-machine-approver-container | cpe:/a:redhat:openshift:4.3::el7 | RHSA-2020:4264 | 2020-10-20T00:00:00Z |
ose-cluster-openshift-apiserver-operator-container | cpe:/a:redhat:openshift:4.3::el7 | RHSA-2020:4264 | 2020-10-20T00:00:00Z |
ose-cluster-openshift-controller-manager-operator-container | cpe:/a:redhat:openshift:4.3::el7 | RHSA-2020:4264 | 2020-10-20T00:00:00Z |
ose-cluster-samples-operator-container | cpe:/a:redhat:openshift:4.3::el7 | RHSA-2020:4264 | 2020-10-20T00:00:00Z |
ose-cluster-storage-operator-container | cpe:/a:redhat:openshift:4.3::el7 | RHSA-2020:4264 | 2020-10-20T00:00:00Z |
ose-cluster-update-keys-container | cpe:/a:redhat:openshift:4.3::el7 | RHSA-2020:4264 | 2020-10-20T00:00:00Z |
ose-etcd-container | cpe:/a:redhat:openshift:4.3::el7 | RHSA-2020:4264 | 2020-10-20T00:00:00Z |
ose-installer-artifacts-container | cpe:/a:redhat:openshift:4.3::el7 | RHSA-2020:4264 | 2020-10-20T00:00:00Z |
ose-installer-container | cpe:/a:redhat:openshift:4.3::el7 | RHSA-2020:4264 | 2020-10-20T00:00:00Z |
ose-libvirt-machine-controllers-container | cpe:/a:redhat:openshift:4.3::el7 | RHSA-2020:4264 | 2020-10-20T00:00:00Z |
ose-machine-api-operator-container | cpe:/a:redhat:openshift:4.3::el7 | RHSA-2020:4264 | 2020-10-20T00:00:00Z |
ose-machine-config-operator-container | cpe:/a:redhat:openshift:4.3::el7 | RHSA-2020:4264 | 2020-10-20T00:00:00Z |
ose-multus-admission-controller-container | cpe:/a:redhat:openshift:4.3::el7 | RHSA-2020:4264 | 2020-10-20T00:00:00Z |
ose-must-gather-container | cpe:/a:redhat:openshift:4.3::el7 | RHSA-2020:4264 | 2020-10-20T00:00:00Z |
ose-openshift-apiserver-container | cpe:/a:redhat:openshift:4.3::el7 | RHSA-2020:4264 | 2020-10-20T00:00:00Z |
ose-openshift-controller-manager-container | cpe:/a:redhat:openshift:4.3::el7 | RHSA-2020:4264 | 2020-10-20T00:00:00Z |
ose-openstack-machine-controllers-container | cpe:/a:redhat:openshift:4.3::el7 | RHSA-2020:4264 | 2020-10-20T00:00:00Z |
ose-ovn-kubernetes-container | cpe:/a:redhat:openshift:4.3::el7 | RHSA-2020:4264 | 2020-10-20T00:00:00Z |
ose-prometheus-adapter-container | cpe:/a:redhat:openshift:4.3::el7 | RHSA-2020:4264 | 2020-10-20T00:00:00Z |
ose-service-ca-operator-container | cpe:/a:redhat:openshift:4.3::el7 | RHSA-2020:4264 | 2020-10-20T00:00:00Z |
prometheus-config-reloader-container | cpe:/a:redhat:openshift:4.3::el7 | RHSA-2020:4264 | 2020-10-20T00:00:00Z |
prometheus-operator-container | cpe:/a:redhat:openshift:4.3::el7 | RHSA-2020:4264 | 2020-10-20T00:00:00Z |
prom-label-proxy-container | cpe:/a:redhat:openshift:4.3::el7 | RHSA-2020:4264 | 2020-10-20T00:00:00Z |
telemeter-container | cpe:/a:redhat:openshift:4.3::el7 | RHSA-2020:4264 | 2020-10-20T00:00:00Z |
Red Hat OpenShift Container Platform 4.3 | |||
openshift-clients-0:4.3.31-202007250052.p0.git.3329.59998b9.el8 | cpe:/a:redhat:openshift:4.3::el7 | RHBA-2020:3179 | 2020-08-05T00:00:00Z |
openshift4/ose-azure-machine-controllers:v4.3.31-202007272153.p0 | cpe:/a:redhat:openshift:4.3::el7 | RHBA-2020:3180 | 2020-08-05T00:00:00Z |
openshift4/ose-sriov-dp-admission-controller:v4.3.37-202009151447.p0 | cpe:/a:redhat:openshift:4.3::el7 | RHSA-2020:3809 | 2020-09-23T00:00:00Z |
Red Hat OpenShift Container Platform 4.4 | |||
openshift4/ose-baremetal-rhel7-operator:v4.4.0-202006290400.p0 | cpe:/a:redhat:openshift:4.4::el7 | RHSA-2020:2789 | 2020-07-06T00:00:00Z |
openshift4/ose-azure-machine-controllers:v4.4.0-202006290400.p0 | cpe:/a:redhat:openshift:4.4::el7 | RHSA-2020:2790 | 2020-07-06T00:00:00Z |
openshift4/ose-descheduler:v4.4.0-202006290400.p0 | cpe:/a:redhat:openshift:4.4::el7 | RHSA-2020:2793 | 2020-07-06T00:00:00Z |
openshift4/ose-cloud-credential-operator:v4.4.0-202007060343.p0 | cpe:/a:redhat:openshift:4.4::el7 | RHSA-2020:2878 | 2020-07-14T00:00:00Z |
openshift4/ose-cluster-machine-approver:v4.4.0-202007171809.p0 | cpe:/a:redhat:openshift:4.4::el7 | RHSA-2020:3078 | 2020-07-28T00:00:00Z |
Red Hat OpenShift Container Platform 4.5 | |||
openshift4/ose-cluster-logging-operator:v4.5.0-202007012112.p0 | cpe:/a:redhat:openshift:4.5::el7 | RHSA-2020:2412 | 2020-07-13T00:00:00Z |
openshift-0:4.5.0-202007012112.p0.git.0.582d7fc.el8 | cpe:/a:redhat:openshift:4.5::el7 | RHSA-2020:2413 | 2020-07-13T00:00:00Z |
openshift4/ose-cluster-kube-descheduler-operator:v4.5.0-202007131801.p0 | cpe:/a:redhat:openshift:4.5::el7 | RHSA-2020:3414 | 2020-08-12T00:00:00Z |
openshift4/ose-descheduler:v4.5.0-202007101023.p0 | cpe:/a:redhat:openshift:4.5::el7 | RHSA-2020:3414 | 2020-08-12T00:00:00Z |
Red Hat OpenShift Container Platform 4.6 | |||
openshift4/ose-elasticsearch-operator:v4.6.0-202010200139.p0 | cpe:/a:redhat:openshift:4.6::el8 | RHSA-2020:4298 | 2020-10-27T00:00:00Z |
Red Hat OpenShift Virtualization 2 | |||
kubevirt-cpu-model-nfd-plugin-container | cpe:/a:redhat:container_native_virtualization:2.6::el8 | RHSA-2021:0799 | 2021-03-10T00:00:00Z |
kubevirt-cpu-node-labeller-container | cpe:/a:redhat:container_native_virtualization:2.6::el8 | RHSA-2021:0799 | 2021-03-10T00:00:00Z |
kubevirt-kvm-info-nfd-plugin-container | cpe:/a:redhat:container_native_virtualization:2.6::el8 | RHSA-2021:0799 | 2021-03-10T00:00:00Z |
vm-import-controller-container | cpe:/a:redhat:container_native_virtualization:2.6::el8 | RHSA-2021:0799 | 2021-03-10T00:00:00Z |
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2020-02-20T00:00:00
Updated: 2024-08-04T10:26:15.873Z
Reserved: 2020-02-19T00:00:00
Link: CVE-2020-9283
Vulnrichment
No data.
NVD
Status : Modified
Published: 2020-02-20T20:15:10.437
Modified: 2023-11-07T03:26:50.740
Link: CVE-2020-9283
Redhat