Panic due to improper verification of cryptographic signatures in golang.org/x/crypto/ssh

Overview

Source
ID
GO-2020-0012
Aliases
CVE-2020-9283
GHSA-ffhg-7mh4-33c4
Affected package

Description

An attacker can craft an ssh-ed25519 or sk-ssh-ed25519@openssh.com public key, such that the library will panic when trying to verify a signature with it. If verifying signatures using user supplied public keys, this may be used as a denial of service vector.

Summary

25.37k
Total packages affected
Packages with at least one version that is affected by the advisory or has an affected dependency.
4.76k
Packages with a known fix
Packages with versions affected by the advisory that have a greater version that is not affected.
1.89%
Total ecosystem affected
The proportion of packages in the ecosystem that are affected by the advisory (fixed or not).
Affected Version: Introduced: 0, Fixed: 0.0.0-20200220183623-bac4c82f6975
Patched/Unaffected
v0.1.0
v0.2.0
v0.3.0
v0.4.0
v0.5.0
v0.6.0
v0.7.0
v0.8.0
v0.9.0
v0.10.0
v0.11.0
v0.12.0
v0.13.0
v0.14.0
v0.15.0
v0.16.0
v0.17.0
v0.18.0
v0.19.0
v0.20.0
v0.21.0
v0.22.0
v0.23.0
v0.24.0
v0.25.0
v0.26.0
v0.27.0
v0.28.0
v0.29.0
v0.30.0
v0.31.0
v0.32.0
v0.33.0
v0.34.0
v0.35.0
v0.36.0
Affected