摘要:
Go before 1.10.8 and 1.11.x before 1.11.5 mishandles P-521 and P-384 elliptic curves, which allows attackers to cause a denial of service (CPU consumption) or possibly conduct ECDH private key recovery attacks.
安全等级: Low
公告ID: KylinSec-SA-2024-3712
发布日期: 2024年9月13日
关联CVE: CVE-2019-6486
Go before 1.10.8 and 1.11.x before 1.11.5 mishandles P-521 and P-384 elliptic curves, which allows attackers to cause a denial of service (CPU consumption) or possibly conduct ECDH private key recovery attacks.
cve名称 | 产品 | 组件 | 是否受影响 |
---|---|---|---|
CVE-2019-6486 | KY3.4-5A | golang | Unaffected |
CVE-2019-6486 | KY3.5.2 | golang | Unaffected |
CVE-2019-6486 | V6 | golang | Unaffected |