CVE-2022-27536
Gentoo Linux Security Advisory 202208-02
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Certificate.Verify in crypto/x509 in Go 1.18.x before 1.18.1 can be caused to panic on macOS when presented with certain malformed certificates. This allows a remote TLS server to cause a TLS client to panic.
Certificate.Verify en crypto/x509 en Go versiones 1.18.x anteriores a 1.18.1, puede causar pánico en macOS cuando son presentados determinados certificados malformados. Esto permite que un servidor TLS remoto cause que un cliente TLS entre en pánico
An update that solves three vulnerabilities and has two fixes is now available. This update for go1.18 fixes the following issues. Fixed a stack overflow in Decode in encoding/pem. Fixed a crash due to refused oversized scalars in generic P-256. Fixed a crash in Certificate.Verify in crypto/x509.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2022-03-21 CVE Reserved
- 2022-04-20 CVE Published
- 2024-08-03 CVE Updated
- 2025-05-08 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-295: Improper Certificate Validation
CAPEC
References (5)
URL | Tag | Source |
---|---|---|
https://cert-portal.siemens.com/productcert/pdf/ssa-744259.pdf |
|
|
https://security.netapp.com/advisory/ntap-20230309-0001 |
|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://groups.google.com/g/golang-announce | 2023-03-09 | |
https://groups.google.com/g/golang-announce/c/oecdBNLOml8 | 2023-03-09 | |
https://security.gentoo.org/glsa/202208-02 | 2023-03-09 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Golang Search vendor "Golang" | Go Search vendor "Golang" for product "Go" | >= 1.18.0 < 1.18.1 Search vendor "Golang" for product "Go" and version " >= 1.18.0 < 1.18.1" | - |
Affected
| in | Apple Search vendor "Apple" | Macos Search vendor "Apple" for product "Macos" | - | - |
Safe
|