Alerts This Week
Warning Icon 1 727
Alerts This Week
Warning Icon 1 727

Debian 10 DLA-3455-1 Critical: golang-go.crypto Message Forgery

debian lts
Calendar Grey June 16, 2023
Dist Debian Esm H88
The recent update for golang-go.crypto addresses a variety of critical vulnerabilities including risks associated with message integrity and safeguarding sensitive information.
Several security vulnerabilities have been discovered in golang-go.crypto, the supplementary Go cryptography libraries

Summary

An issue was discovered in supplementary Go cryptography libraries, aka
golang-googlecode-go-crypto. If more than 256 GiB of keystream is
generated, or if the counter otherwise grows greater than 32 bits, the
amd64 implementation will first generate incorrect output, and then cycle
back to previously generated keystream. Repeated keystream bytes can lead
to loss of confidentiality in encryption applications, or to predictability
in CSPRNG applications.

CVE-2019-11841

A message-forgery issue was discovered in
crypto/openpgp/clearsign/clearsign.go in supplementary Go cryptography
libraries. The "Hash" Armor Header specifies the message digest
algorithm(s) used for the signature. Since the library skips Armor Header
parsing in general, an attacker can not only embed arbitrary Armor Headers,
but also prepend arbitrary text to cleartext messages without invalidating
the signatures.

CVE-2020-9283

Read the Full Advisory


Severity
critical
Lowest
Low
Medium
High
Critical

-------------------------------------------------------------------------Package: golang-go.crypto
Version: 1:0.0~git20181203.505ab14-1+deb10u1
CVE ID: CVE-2019-11840 CVE-2019-11841 CVE-2020-9283
Debian Bug: 952462

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here