CVE-2016-9123Integer Overflow or Wraparound in Square Go-jose

Severity
7.5HIGHNVD
EPSS
0.3%
top 49.07%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 28
Latest updateJun 23

Description

go-jose before 1.0.5 suffers from a CBC-HMAC integer overflow on 32-bit architectures. An integer overflow could lead to authentication bypass for CBC-HMAC encrypted ciphertexts on 32-bit architectures.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:NExploitability: 3.9 | Impact: 3.6

Affected Packages2 packages

Gogithub.com/square_go-jose< 0.0.0-20160903044734-789a4c4bd4c1+1

Patches

🔴Vulnerability Details

5
GHSA
Integer Overflow in go-jose2021-06-23
OSV
Integer Overflow in go-jose2021-06-23
OSV
Integer overflow in github.com/square/go-jose2021-04-14
CVEList
CVE-2016-9123: go-jose before 12017-03-28
OSV
CVE-2016-9123: go-jose before 12017-03-28

📋Vendor Advisories

1
Debian
CVE-2016-9123: golang-gopkg-square-go-jose.v1 - go-jose before 1.0.5 suffers from a CBC-HMAC integer overflow on 32-bit architec...2016
CVE-2016-9123 — Integer Overflow or Wraparound | cvebase