CVE-2018-16875
Summary
| CVE | CVE-2018-16875 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-12-14 14:29:00 UTC |
| Updated | 2023-11-07 02:53:00 UTC |
| Description | The crypto/x509 package of Go before 1.10.6 and 1.11.x before 1.11.3 does not limit the amount of work performed for each chain verification, which might allow attackers to craft pathological inputs leading to a CPU denial of service. Go TLS servers accepting client certificates and TLS clients are affected. |
Risk And Classification
Problem Types: CWE-295
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| [security-announce] openSUSE-SU-2019:1444-1: important: Security update | SUSE | lists.opensuse.org | |
| Google Groups | groups.google.com | ||
| Google Groups | MISC | groups.google.com | Third Party Advisory |
| [security-announce] openSUSE-SU-2019:1079-1: important: Security update | SUSE | lists.opensuse.org | Third Party Advisory |
| [security-announce] openSUSE-SU-2019:1499-1: important: Security update | SUSE | lists.opensuse.org | |
| 1657565 – (CVE-2018-16875) CVE-2018-16875 golang: crypto/x509 allows for denial of service via crafted TLS client certificate | CONFIRM | bugzilla.redhat.com | Issue Tracking, Third Party Advisory |
| [security-announce] openSUSE-SU-2019:1506-1: important: Security update | SUSE | lists.opensuse.org | |
| [security-announce] openSUSE-SU-2019:1703-1: moderate: Security update f | SUSE | lists.opensuse.org | |
| Go: Multiple vulnerabilities (GLSA 201812-09) — Gentoo security | GENTOO | security.gentoo.org | Mitigation, Third Party Advisory |
| Golang Go CVE-2018-16875 Remote Denial of Service Vulnerability | BID | www.securityfocus.com | Third Party Advisory, VDB Entry |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.