The Verify function in crypto/dsa/dsa.go in Go before 1.5.4 and 1.6.x before 1.6.1 does not properly check parameters passed to the big integer library, which might allow remote attackers to cause a denial of service (infinite loop) via a crafted public key to a program that uses HTTPS client certificates or SSH server libraries.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade go | Sep 20, 2017 | May 23, 2016 |
| Amazon_linux | — | Upgrade golang | Apr 21, 2016 | Apr 21, 2016 |
| Centos_linux | — | Upgrade golang-docsUpgrade golang-testsUpgrade golangUpgrade golang-binUpgrade golang-srcUpgrade golang-misc | Oct 19, 2017 | May 23, 2016 |
| Freebsd | — | Upgrade go | Dec 10, 2025 | Apr 14, 2016 |
| Oracle Solaris | — | Upgrade entire/ to version 11.4-11.4.0.0.1.15.0 on Solaris 11.4 | Oct 19, 2018 | May 23, 2016 |
| Redhat_linux | — | Upgrade golang-srcUpgrade golang-miscUpgrade golang-binUpgrade golang-testsUpgrade golangUpgrade golang-docs | Oct 21, 2016 | May 23, 2016 |
| Suse | — | Upgrade go-docUpgrade go-debuginfoUpgrade goUpgrade go-debugsource | May 19, 2016 | May 18, 2016 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub