Lucene search

K
ibmIBMA288246DC86E48BD2F3A2D08FAC3145CCDB418F32D573E1FC72FF44F7AE6C53D
HistoryFeb 26, 2020 - 4:07 p.m.

Security Bulletin: IBM MQ certified container is vulnerable to a denial of service vulnerability in golang (CVE-2019-17596)

2020-02-2616:07:05
www.ibm.com
11

EPSS

0.004

Percentile

74.1%

Summary

A vulnerability was discovered in golang which is used to create the control programs used by IBM MQ certified container.

Vulnerability Details

CVEID:CVE-2019-17596
**DESCRIPTION:**Golang Go is vulnerable to a denial of service, caused by a flaw when verifying invalid DSA public key. By sending a specially-crafted request containing an invalid DSA public key, a remote attacker could exploit this vulnerability to cause a denial of service condition.
CVSS Base score: 7.5
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/170191 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)

Affected Products and Versions

Affected Product(s) Version(s)
IBM MQ certified Container 4.x.x CD

Remediation/Fixes

IBM MQ certified container

Upgrade to version 4.1.2

Workarounds and Mitigations

None