Total vulnerabilities in the database
Go before 1.10.8 and 1.11.x before 1.11.5 mishandles P-521 and P-384 elliptic curves, which allows attackers to cause a denial of service (CPU consumption) or possibly conduct ECDH private key recovery attacks.
Software | From | Fixed in |
---|---|---|
golang / go | 1.11.1 | 1.11.5 |
golang / go | - | 1.10.8 |
debian / debian_linux | 8.0 | 8.0.x |
debian / debian_linux | 9.0 | 9.0.x |
opensuse / leap | 15.0 | 15.0.x |