Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:4101
HistoryMay 03, 2017 - 2:32 a.m.

Denial Of Service (DoS)

2017-05-0302:32:06
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
10

0.027 Low

EPSS

Percentile

90.6%

crypto/dsa in github.com/golang/go is vulnerable to denial of service (DoS) attacks. These attacks are possible due to a flaw in the Verify function in crypto/dsa/dsa.go. It doesn’t properly check parameters passed to the big integer library. This flaw can be exploited through a a public key given to a program that uses HTTPS client certificates or SSH server libraries.