DirectorySecurity Advisories
Sign In
Security Advisories

CGA-28f7-9mwr-qjvg

Published

Last updated

https://images.chainguard.dev/security/CGA-28f7-9mwr-qjvg
Package

k3d

Latest Update
Fixed
Fixed Version

5.6.0-r11

Aliases
  • CVE-2020-29652
  • GHSA-3vm4-22fp-5rfm

Severity

7.5

High

CVSS V3

Summary

golang.org/x/crypto/ssh NULL Pointer Dereference vulnerability

Description

A nil pointer dereference in the golang.org/x/crypto/ssh component through v0.0.0-20201203163018-be400aefbc4c for Go allows remote attackers to cause a denial of service against SSH servers. An attacker can craft an authentication request message for the gssapi-with-mic method which will cause NewServerConn to panic via a nil pointer dereference if ServerConfig.GSSAPIWithMICConfig is nil.

References

Updates


Safe Source for Open Sourceâ„¢
Media KitContact Us
© 2024 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Product

Chainguard Images