Misleading message verification in golang.org/x/crypto/openpgp/clearsign

Overview

Source
ID
GO-2023-1992
Aliases
CVE-2019-11841
GHSA-x3jr-pf6g-c48f
Affected package

Description

The clearsign package accepts some malformed messages, making it possible for an attacker to trick a human user (but not a Go program) into thinking unverified text is part of the message.

With fix, messages with malformed headers in the SIGNED MESSAGE section are rejected.

Summary

10.07k
Total packages affected
Packages with at least one version that is affected by the advisory or has an affected dependency.
2.52k
Packages with a known fix
Packages with versions affected by the advisory that have a greater version that is not affected.
0.75%
Total ecosystem affected
The proportion of packages in the ecosystem that are affected by the advisory (fixed or not).
Affected Version: Introduced: 0, Fixed: 0.0.0-20190424203555-c05e17bb3b2d
Patched/Unaffected
v0.1.0
v0.2.0
v0.3.0
v0.4.0
v0.5.0
v0.6.0
v0.7.0
v0.8.0
v0.9.0
v0.10.0
v0.11.0
v0.12.0
v0.13.0
v0.14.0
v0.15.0
v0.16.0
v0.17.0
v0.18.0
v0.19.0
v0.20.0
v0.21.0
v0.22.0
v0.23.0
v0.24.0
v0.25.0
v0.26.0
v0.27.0
v0.28.0
v0.29.0
v0.30.0
v0.31.0
v0.32.0
v0.33.0
v0.34.0
v0.35.0
v0.36.0
Affected