Golang Go CVE-2018-16875 Remote Denial of Service Vulnerability
BID:106230
CVE-2018-16875 |Info
Golang Go CVE-2018-16875 Remote Denial of Service Vulnerability
| Bugtraq ID: | 106230 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2018-16875 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 13 2018 12:00AM |
| Updated: | Dec 13 2018 12:00AM |
| Credit: | Netflix |
| Vulnerable: |
Redhat Gluster Storage 3.0 Redhat Ceph Storage 3 Redhat Ceph Storage 2 golang Go 1.11.2 golang Go 1.11.1 golang Go 1.10.5 golang Go 1.10.4 golang Go 1.10.3 golang Go 1.10.2 golang Go 1.10.1 golang Go 1.11 golang Go 1.10 |
| Not Vulnerable: |
golang Go 1.11.3 golang Go 1.10.6 |
Solution / Fix
Golang Go CVE-2018-16875 Remote Denial of Service Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Golang Go CVE-2018-16875 Remote Denial of Service Vulnerability
References:
References:
- [security] Go 1.11.3 and Go 1.10.6 pre-announcement (Google)
- Bug 1657565 (CVE-2018-16875) - CVE-2018-16875 golang: crypto/x509 allows for den (Red Hat Bugzilla)
- CVE-2018-16875 (Red Hat Bugzilla)
- Go Homepage (golang)
- crypto/x509: CPU denial of service in chain validation (Golang)