Skip to content

x/vulndb: potential Go vuln in Go Standard Library (package not identified): CVE-2020-29652 #227

@GoVulnBot

Description

@GoVulnBot

In CVE-2020-29652, the reference URL [Go Standard Library (package not identified)](Go Standard Library (package not identified)) (and possibly others) refers to something in Go.

module: std
package: Go Standard Library (package not identified)
description: |
  A nil pointer dereference in the golang.org/x/crypto/ssh component through v0.0.0-20201203163018-be400aefbc4c for Go allows remote attackers to cause a denial of service against SSH servers.
cves:
- CVE-2020-29652
links:
  pr: https://go-review.googlesource.com/c/crypto/+/278852
  context:
  - https://groups.google.com/g/golang-announce/c/ouZIlBimOsE?pli=1
  - https://lists.apache.org/thread.html/r68032132c0399c29d6cdc7bd44918535da54060a10a12b1591328bff@%3Cnotifications.skywalking.apache.org%3E

See doc/triage.md for instructions on how to triage this report.

Metadata

Metadata

Assignees

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions