Lucene search

K
osvGoogleOSV:GO-2020-0012
HistoryApr 14, 2021 - 8:04 p.m.

Panic due to improper verification of cryptographic signatures in golang.org/x/crypto/ssh

2021-04-1420:04:52
Google
osv.dev
9

0.244 Low

EPSS

Percentile

96.6%

An attacker can craft an ssh-ed25519 or [email protected] public key, such that the library will panic when trying to verify a signature with it. If verifying signatures using user supplied public keys, this may be used as a denial of service vector.