CVE-2020-9283
Go SSH servers 0.0.2 - Denial of Service (PoC)
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
4Exploited in Wild
-Decision
Descriptions
golang.org/x/crypto before v0.0.0-20200220183623-bac4c82f6975 for Go allows a panic during signature verification in the golang.org/x/crypto/ssh package. A client can attack an SSH server that accepts public keys. Also, a server can attack any SSH client.
golang.org/x/crypto versiones anteriores a v0.0.0-20200220183623-bac4c82f6975, para Go permite un pánico durante la comprobación de firma en el paquete golang.org/x/crypto/ssh. Un cliente puede atacar un servidor SSH que acepte claves públicas. Además, un servidor puede atacar a cualquier cliente SSH.
A denial of service vulnerability was found in the SSH package of the golang.org/x/crypto library. An attacker could exploit this flaw by supplying crafted SSH ed25519 keys to cause a crash in applications that use this package as either an SSH client or server.
Red Hat 3scale API Management delivers centralized API management features through a distributed, cloud-hosted layer. It includes built-in features to help in building a more successful API program, including access control, rate limits, payment gateway integration, and developer experience tools. This advisory is intended to use with container images for Red Hat 3scale API Management 2.10.0.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2020-02-19 CVE Reserved
- 2020-02-20 CVE Published
- 2020-02-23 First Exploit
- 2024-08-04 CVE Updated
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-130: Improper Handling of Length Parameter Inconsistency
- CWE-347: Improper Verification of Cryptographic Signature
CAPEC
References (11)
URL | Date | SRC |
---|---|---|
https://packetstorm.news/files/id/156480 | 2020-02-23 | |
https://www.exploit-db.com/exploits/48121 | 2020-02-24 | |
https://github.com/brompwnie/CVE-2020-9283 | 2020-06-08 | |
http://packetstormsecurity.com/files/156480/Go-SSH-0.0.2-Denial-Of-Service.html | 2024-08-04 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://access.redhat.com/security/cve/CVE-2020-9283 | 2021-04-08 | |
https://bugzilla.redhat.com/show_bug.cgi?id=1804533 | 2021-04-08 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Golang Search vendor "Golang" | Package Ssh Search vendor "Golang" for product "Package Ssh" | 0.0.0-20200220183623-bac4c82f6975 Search vendor "Golang" for product "Package Ssh" and version "0.0.0-20200220183623-bac4c82f6975" | - |
Affected
| ||||||
Debian Search vendor "Debian" | Debian Linux Search vendor "Debian" for product "Debian Linux" | 9.0 Search vendor "Debian" for product "Debian Linux" and version "9.0" | - |
Affected
|