Oval Definition:oval:com.ubuntu.cosmic:def:2018168750000000
Revision Date:2018-12-14Version:1
Title:CVE-2018-16875 on Ubuntu 18.10 (cosmic) - low.
Description:The crypto/x509 package of Go before 1.10.6 and 1.11.x before 1.11.3 does not limit the amount of work performed for each chain verification, which might allow attackers to craft pathological inputs leading to a CPU denial of service. Go TLS servers accepting client certificates and TLS clients are affected.
Family:unixClass:vulnerability
Status:Reference(s):CVE-2018-16875
Platform(s):Ubuntu 18.10
Product(s):
Definition Synopsis
  • Ubuntu 18.10 (cosmic) is installed.
  • AND Package Information
  • golang-1.10: while related to the CVE in some way, a decision has been made to ignore this issue (note: 'reached end-of-life').
  • OR golang-1.7: while related to the CVE in some way, a decision has been made to ignore this issue (note: 'reached end-of-life').
  • OR golang-1.8: while related to the CVE in some way, a decision has been made to ignore this issue (note: 'reached end-of-life').
  • OR golang-1.9: while related to the CVE in some way, a decision has been made to ignore this issue (note: 'reached end-of-life').
  • BACK