CVE-2020-9283
Go SSH servers 0.0.2 - Denial of Service (PoC)
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
3Exploited in Wild
-Decision
Descriptions
golang.org/x/crypto before v0.0.0-20200220183623-bac4c82f6975 for Go allows a panic during signature verification in the golang.org/x/crypto/ssh package. A client can attack an SSH server that accepts public keys. Also, a server can attack any SSH client.
golang.org/x/crypto versiones anteriores a v0.0.0-20200220183623-bac4c82f6975, para Go permite un pánico durante la comprobación de firma en el paquete golang.org/x/crypto/ssh. Un cliente puede atacar un servidor SSH que acepte claves públicas. Además, un servidor puede atacar a cualquier cliente SSH.
A denial of service vulnerability was found in the SSH package of the golang.org/x/crypto library. An attacker could exploit this flaw by supplying crafted SSH ed25519 keys to cause a crash in applications that use this package as either an SSH client or server.
Go SSH server version 0.0.2 suffers from a denial of service vulnerability.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2020-02-19 CVE Reserved
- 2020-02-20 CVE Published
- 2020-02-24 First Exploit
- 2024-08-04 CVE Updated
- 2024-10-17 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-130: Improper Handling of Length Parameter Inconsistency
- CWE-347: Improper Verification of Cryptographic Signature
CAPEC
References (10)
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/48121 | 2020-02-24 | |
https://github.com/brompwnie/CVE-2020-9283 | 2020-06-08 | |
http://packetstormsecurity.com/files/156480/Go-SSH-0.0.2-Denial-Of-Service.html | 2024-08-04 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://access.redhat.com/security/cve/CVE-2020-9283 | 2021-04-08 | |
https://bugzilla.redhat.com/show_bug.cgi?id=1804533 | 2021-04-08 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Golang Search vendor "Golang" | Package Ssh Search vendor "Golang" for product "Package Ssh" | 0.0.0-20200220183623-bac4c82f6975 Search vendor "Golang" for product "Package Ssh" and version "0.0.0-20200220183623-bac4c82f6975" | - |
Affected
| ||||||
Debian Search vendor "Debian" | Debian Linux Search vendor "Debian" for product "Debian Linux" | 9.0 Search vendor "Debian" for product "Debian Linux" and version "9.0" | - |
Affected
|