CVE-2019-17596
published 2019-10-24CVE-2019-17596: Go before 1.12.11 and 1.3.x before 1.13.2 can panic upon an attempt to process network traffic containing an invalid DSA public key. There are several attack…
PriorityP343high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
4.69%
90.8th percentile
Go before 1.12.11 and 1.3.x before 1.13.2 can panic upon an attempt to process network traffic containing an invalid DSA public key. There are several attack scenarios, such as traffic from a client to a server that verifies client certificates.
Affected
25 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| arista | cloudvision_portal | — | — |
| arista | cloudvision_portal | — | — |
| arista | cloudvision_portal | — | — |
| arista | cloudvision_portal | 2018.1.0 – 2018.2.3 | — |
| arista | eos | <= 4.23.1f | — |
| arista | mos | <= 0.25 | — |
| arista | terminattr | <= 1.7.2 | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| golang | go | >= 1.12 < 1.12.11 | 1.12.11 |
| golang | go | >= 1.13 < 1.13.2 | 1.13.2 |
| msrc | azl3_golang_1.23.7-1_on_azure_linux_3.0 | — | — |
| msrc | azl3_golang_1.23.9-1_on_azure_linux_3.0 | — | — |
| msrc | azl3_golang_1.24.3-1_on_azure_linux_3.0 | — | — |
| msrc | azl3_python-tensorboard_2.11.0-3_on_azure_linux_3.0 | — | — |
| msrc | azl3_python-tensorboard_2.16.2-2_on_azure_linux_3.0 | — | — |
| msrc | azure_linux_3.0_arm | — | — |
| msrc | azure_linux_3.0_x64 | — | — |
| opensuse | leap | — | — |
| opensuse | leap | — | — |
| redhat | developer_tools | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux_server | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv7.5HIGH
vendor_msrc7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Panic on invalid DSA public keys in crypto/dsa
osv·2022-05-24
CVE-2019-17596 Panic on invalid DSA public keys in crypto/dsa
Panic on invalid DSA public keys in crypto/dsa
Invalid DSA public keys can cause a panic in dsa.Verify. In particular, using crypto/x509.Verify on a crafted X.509 certificate chain can lead to a panic, even if the certificates don't chain to a trusted root. The chain can be delivered via a crypto/tls connection to a client, or to a server that accepts and verifies client certificates. net/http clients can be made to crash by an HTTPS server, while net/http servers that accept client certificates will recover the panic and are unaffected.
Moreover, an application might crash invoking crypto/x509.(*CertificateRequest).CheckSignature on an X.509 certificate request, parsing a golang.org/x/crypto/openpgp Entity, or during a golang.org/x/crypto/otr conversation. Finally, a golang.org/x/crypto
GHSA
GHSA-gcr4-wcqh-3624: Go before 1
ghsa_unreviewed·2022-05-24
CVE-2019-17596 [MEDIUM] CWE-436 GHSA-gcr4-wcqh-3624: Go before 1
Go before 1.12.11 and 1.3.x before 1.13.2 can panic upon an attempt to process network traffic containing an invalid DSA public key. There are several attack scenarios, such as traffic from a client to a server that verifies client certificates.
OSV
CVE-2019-17596: Go before 1
osv·2019-10-24·CVSS 7.5
CVE-2019-17596 [HIGH] CVE-2019-17596: Go before 1
Go before 1.12.11 and 1.3.x before 1.13.2 can panic upon an attempt to process network traffic containing an invalid DSA public key. There are several attack scenarios, such as traffic from a client to a server that verifies client certificates.
Red Hat
golang: invalid public key causes panic in dsa.Verify
vendor_redhat·2019-10-17·CVSS 7.5
CVE-2019-17596 [HIGH] CWE-295 golang: invalid public key causes panic in dsa.Verify
golang: invalid public key causes panic in dsa.Verify
Go before 1.12.11 and 1.3.x before 1.13.2 can panic upon an attempt to process network traffic containing an invalid DSA public key. There are several attack scenarios, such as traffic from a client to a server that verifies client certificates.
Package: golang (Red Hat Ceph Storage 2) - Out of support scope
Package: golang (Red Hat Ceph Storage 3) - Will not fix
Package: grafana (Red Hat Ceph Storage 3) - Not affected
Package: golang (Red Hat Enterprise Linux 7) - Out of support scope
Package: atomic-openshift (Red Hat OpenShift Container Platform 3.10) - Out of support scope
Package: atomic-openshift (Red Hat OpenShift Container Platform 3.11) - Out of support scope
Package: atomic-openshift (Red Hat OpenShift Container Platfo
Microsoft
Go before 1.12.11 and 1.3.x before 1.13.2 can panic upon an attempt to process network traffic containing an invalid DSA public key. There are several attack scenarios such as traffic from a client to
vendor_msrc·2019-10-08·CVSS 7.5
CVE-2019-17596 [HIGH] CWE-436 Go before 1.12.11 and 1.3.x before 1.13.2 can panic upon an attempt to process network traffic containing an invalid DSA public key. There are several attack scenarios such as traffic from a client to
Go before 1.12.11 and 1.3.x before 1.13.2 can panic upon an attempt to process network traffic containing an invalid DSA public key. There are several attack scenarios such as traffic from a client to a server that verifies client certificates.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additiona
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-17596 golang: invalid public key causes panic in dsa.Verify [epel-all]
bugzilla·2019-10-18·CVSS 7.5
CVE-2019-17596 [HIGH] CVE-2019-17596 golang: invalid public key causes panic in dsa.Verify [epel-all]
CVE-2019-17596 golang: invalid public key causes panic in dsa.Verify [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions
Bugzilla
CVE-2019-17596 golang: invalid public key causes panic in dsa.Verify
bugzilla·2019-10-18·CVSS 7.5
CVE-2019-17596 [HIGH] CVE-2019-17596 golang: invalid public key causes panic in dsa.Verify
CVE-2019-17596 golang: invalid public key causes panic in dsa.Verify
As announced by Go upstream on 2019-10-17: Invalid DSA public keys can cause a panic in dsa.Verify. In particular, using crypto/x509.Verify on a crafted X.509 certificate chain can lead to a panic, even if the certificates don’t chain to a trusted root. The chain can be delivered via a crypto/tls connection to a client, or to a server that accepts and verifies client certificates. net/http clients can be made to crash by an HTTPS server, while net/http servers that accept client certificates will recover the panic and are unaffected.
Moreover, an application might crash invoking crypto/x509.(*CertificateRequest) CheckSignature on an X.509 certificate request, parsing a golang.org/x/crypto/openpgp Entity, or during a gol
Bugzilla
CVE-2019-17596 golang: invalid public key causes panic in dsa.Verify [fedora-all]
bugzilla·2019-10-18·CVSS 7.5
CVE-2019-17596 [HIGH] CVE-2019-17596 golang: invalid public key causes panic in dsa.Verify [fedora-all]
CVE-2019-17596 golang: invalid public key causes panic in dsa.Verify [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported vers
http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00043.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-11/msg00044.htmlhttps://access.redhat.com/errata/RHSA-2020:0101https://access.redhat.com/errata/RHSA-2020:0329https://github.com/golang/go/issues/34960https://groups.google.com/d/msg/golang-announce/lVEm7llp0w0/VbafyRkgCgAJhttps://lists.debian.org/debian-lts-announce/2021/03/msg00014.htmlhttps://lists.debian.org/debian-lts-announce/2021/03/msg00015.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/5VS3HPSE25ZSGS4RSOTADC67YNOHIGVV/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WVOWGM7IQGRO7DS2MCUMYZRQ4TYOZNAS/https://security.netapp.com/advisory/ntap-20191122-0005/https://www.arista.com/en/support/advisories-notices/security-advisories/10134-security-advisory-46https://www.debian.org/security/2019/dsa-4551http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00043.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-11/msg00044.htmlhttps://access.redhat.com/errata/RHSA-2020:0101https://access.redhat.com/errata/RHSA-2020:0329https://github.com/golang/go/issues/34960https://groups.google.com/d/msg/golang-announce/lVEm7llp0w0/VbafyRkgCgAJhttps://lists.debian.org/debian-lts-announce/2021/03/msg00014.htmlhttps://lists.debian.org/debian-lts-announce/2021/03/msg00015.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/5VS3HPSE25ZSGS4RSOTADC67YNOHIGVV/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WVOWGM7IQGRO7DS2MCUMYZRQ4TYOZNAS/https://security.netapp.com/advisory/ntap-20191122-0005/https://www.arista.com/en/support/advisories-notices/security-advisories/10134-security-advisory-46https://www.debian.org/security/2019/dsa-4551
2019-10-24
Published