Vulnerability Name:

CVE-2019-17596 (CCN-170191)

Assigned:2019-10-17
Published:2019-10-17
Updated:2021-11-30
Summary:Go before 1.12.11 and 1.3.x before 1.13.2 can panic upon an attempt to process network traffic containing an invalid DSA public key. There are several attack scenarios, such as traffic from a client to a server that verifies client certificates.
CVSS v3 Severity:7.5 High (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
6.5 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): High
7.5 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
6.5 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): High
7.5 High (REDHAT CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
6.5 Medium (REDHAT Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): High
CVSS v2 Severity:5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Partial
7.8 High (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Complete
Vulnerability Type:CWE-436
CWE-295
Vulnerability Consequences:Denial of Service
References:Source: MITRE
Type: CNA
CVE-2019-17596

Source: SUSE
Type: Mailing List, Third Party Advisory
openSUSE-SU-2019:2522

Source: SUSE
Type: Mailing List, Third Party Advisory
openSUSE-SU-2019:2521

Source: REDHAT
Type: Third Party Advisory
RHSA-2020:0101

Source: REDHAT
Type: Third Party Advisory
RHSA-2020:0329

Source: XF
Type: UNKNOWN
go-cve201917596-dos(170191)

Source: CCN
Type: go GIT Repository
crypto/dsa: invalid public key causes panic in dsa.Verify #34960

Source: CONFIRM
Type: Exploit, Issue Tracking, Patch, Third Party Advisory
https://github.com/golang/go/issues/34960

Source: CONFIRM
Type: Release Notes, Third Party Advisory
https://groups.google.com/d/msg/golang-announce/lVEm7llp0w0/VbafyRkgCgAJ

Source: MLIST
Type: Mailing List, Third Party Advisory
[debian-lts-announce] 20210313 [SECURITY] [DLA 2591-1] golang-1.7 security update

Source: MLIST
Type: Mailing List, Third Party Advisory
[debian-lts-announce] 20210313 [SECURITY] [DLA 2592-1] golang-1.8 security update

Source: FEDORA
Type: Mailing List, Third Party Advisory
FEDORA-2019-4593120208

Source: FEDORA
Type: Mailing List, Third Party Advisory
FEDORA-2019-34e097c66c

Source: CONFIRM
Type: Third Party Advisory
https://security.netapp.com/advisory/ntap-20191122-0005/

Source: MISC
Type: Third Party Advisory
https://www.arista.com/en/support/advisories-notices/security-advisories/10134-security-advisory-46

Source: DEBIAN
Type: Third Party Advisory
DSA-4551

Source: CCN
Type: IBM Security Bulletin 1283668 (API Connect)
IBM API Connect is impacted by vulnerabilities in Golang (CVE-2019-17596)

Source: CCN
Type: IBM Security Bulletin 2495361 (Cloud Private)
A Security Vulnerability affects IBM Cloud Private - Go (CVE-2019-17596)

Source: CCN
Type: IBM Security Bulletin 3546351 (MQ CloudPak)
IBM MQ certified container is vulnerable to a denial of service vulnerability in golang (CVE-2019-17596)

Source: CCN
Type: IBM Security Bulletin 6205725 (Cloud Automation Manager)
A Security Vulnerability affects IBM Cloud Automation Manager - Go (CVE-2019-17596)

Source: CCN
Type: IBM Security Bulletin 6323255 (ICP Discovery)
IBM Watson Discovery for IBM Cloud Pak for Data affected by vulnerability in Go

Source: CCN
Type: IBM Security Bulletin 6412335 (Cloud Pak for Multicloud Management)
Security vulnerabilities in Go affect IBM Cloud Pak for Multicloud Management Hybrid GRC.

Source: CCN
Type: IBM Security Bulletin 6449298 (Watson Machine Learning)
Go can panic upon an attempt to process network traffic on IBM Watson Machine Learning on CP4D

Source: CCN
Type: WhiteSource Vulnerability Database
CVE-2019-17596

Vulnerable Configuration:Configuration 1:
  • cpe:/a:golang:go:*:*:*:*:*:*:*:* (Version >= 1.13 and < 1.13.2)
  • OR cpe:/a:golang:go:*:*:*:*:*:*:*:* (Version >= 1.12 and < 1.12.11)

  • Configuration 2:
  • cpe:/o:debian:debian_linux:9.0:*:*:*:*:*:*:*
  • OR cpe:/o:debian:debian_linux:10.0:*:*:*:*:*:*:*

  • Configuration 3:
  • cpe:/o:fedoraproject:fedora:30:*:*:*:*:*:*:*
  • OR cpe:/o:fedoraproject:fedora:31:*:*:*:*:*:*:*

  • Configuration 4:
  • cpe:/a:redhat:developer_tools:1.0:*:*:*:*:*:*:*
  • OR cpe:/o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*
  • OR cpe:/o:redhat:enterprise_linux_server:8.1:*:*:*:*:*:*:*

  • Configuration 5:
  • cpe:/o:opensuse:leap:15.0:*:*:*:*:*:*:*
  • OR cpe:/o:opensuse:leap:15.1:*:*:*:*:*:*:*

  • Configuration 6:
  • cpe:/a:arista:cloudvision_portal:*:*:*:*:*:*:*:* (Version >= 2018.1.0 and <= 2018.2.3)
  • OR cpe:/a:arista:cloudvision_portal:2019.1.0:*:*:*:*:*:*:*
  • OR cpe:/a:arista:cloudvision_portal:2019.1.1:*:*:*:*:*:*:*
  • OR cpe:/a:arista:cloudvision_portal:2019.1.2:*:*:*:*:*:*:*
  • OR cpe:/a:arista:terminattr:*:*:*:*:*:*:*:* (Version <= 1.7.2)
  • OR cpe:/o:arista:eos:*:*:*:*:*:*:*:* (Version <= 4.23.1f)
  • OR cpe:/o:arista:mos:*:*:*:*:*:*:*:* (Version <= 0.25)

  • Configuration RedHat 1:
  • cpe:/a:redhat:enterprise_linux:8:*:*:*:*:*:*:*

  • Configuration RedHat 2:
  • cpe:/a:redhat:enterprise_linux:8::appstream:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:golang:go:1.12.10:*:*:*:*:*:*:*
  • OR cpe:/a:golang:go:1.13.1:*:*:*:*:*:*:*
  • AND
  • cpe:/a:ibm:api_connect:2018.4.1.0:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:cloud_private:3.2.0:cd:*:*:*:*:*:*
  • OR cpe:/a:ibm:cloud_private:3.2.1:cd:*:*:*:*:*:*
  • OR cpe:/a:ibm:api_connect:2018.4.1.9:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:cloud_automation_manager:3.2.1.0:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:51965
    P
    Security update for libdb-4_8 (Low)
    2022-11-24
    oval:org.opensuse.security:def:201917596
    V
    CVE-2019-17596
    2022-06-30
    oval:org.opensuse.security:def:3313
    P
    ovmf-2017+git1510945757.b2662641d5-3.16.1 on GA media (Moderate)
    2022-06-28
    oval:org.opensuse.security:def:3325
    P
    perl-Config-IniFiles-2.82-3.12 on GA media (Moderate)
    2022-06-28
    oval:org.opensuse.security:def:3582
    P
    libcdio14-0.90-6.3.1 on GA media (Moderate)
    2022-06-28
    oval:org.opensuse.security:def:3594
    P
    libgc1-7.2d-5.1 on GA media (Moderate)
    2022-06-28
    oval:org.opensuse.security:def:2875
    P
    bcm43xx-firmware-20180314-150400.28.5 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:2934
    P
    glib2-devel-2.70.4-150400.1.5 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:2857
    P
    Mesa-21.2.4-150400.66.1 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:2904
    P
    cyrus-sasl-saslauthd-2.1.27-150300.4.6.1 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:2889
    P
    clamav-0.103.5-3.35.1 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:2942
    P
    groff-1.22.4-150400.3.4 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:2944
    P
    gssproxy-0.8.2-3.9.1 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:2863
    P
    apparmor-abstractions-3.0.4-150400.3.4 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:2928
    P
    gdk-pixbuf-devel-2.42.6-150400.3.8 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:2895
    P
    cpp7-7.5.0+r278197-4.30.1 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:112331
    P
    go1.12-1.12.17-4.8 on GA media (Moderate)
    2022-01-17
    oval:org.opensuse.security:def:112332
    P
    go1.13-1.13.15-2.6 on GA media (Moderate)
    2022-01-17
    oval:org.opensuse.security:def:113041
    P
    notary-0.7.0-1.2 on GA media (Moderate)
    2022-01-17
    oval:org.opensuse.security:def:74330
    P
    Security update for ImageMagick (Moderate)
    2021-12-10
    oval:org.opensuse.security:def:51696
    P
    Security update for the Linux Kernel (Live Patch 40 for SLE 12 SP3) (Important)
    2021-11-19
    oval:org.opensuse.security:def:105853
    P
    Security update for salt (Moderate)
    2021-10-27
    oval:org.opensuse.security:def:105852
    P
    go1.12-1.12.17-4.8 on GA media (Moderate)
    2021-10-01
    oval:org.opensuse.security:def:106481
    P
    notary-0.7.0-1.2 on GA media (Moderate)
    2021-10-01
    oval:org.opensuse.security:def:49452
    P
    Security update for nodejs14 (Important)
    2021-09-22
    oval:org.opensuse.security:def:63203
    P
    dpdk-18.11-2.43 on GA media (Moderate)
    2021-09-21
    oval:org.opensuse.security:def:63341
    P
    libmariadb-devel-3.1.12-3.25.1 on GA media (Moderate)
    2021-08-10
    oval:org.opensuse.security:def:63001
    P
    ctags-5.8-1.27 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:72078
    P
    tboot-20170711_1.9.8-15.9.1 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:51758
    P
    Security update for wavpack (Important)
    2021-03-24
    oval:org.opensuse.security:def:49120
    P
    Security update for rubygem-archive-tar-minitar (Moderate)
    2021-01-13
    oval:org.opensuse.security:def:52027
    P
    Security update for MozillaFirefox (Important)
    2021-01-12
    oval:org.opensuse.security:def:64278
    P
    Security update for clamav (Moderate)
    2020-12-14
    oval:org.opensuse.security:def:72194
    P
    libtiff5-32bit-4.0.9-3.15 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:62722
    P
    typelib-1_0-JavaScriptCore-4_0-2.28.2-1.11 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:62521
    P
    gdm-3.26.2.1-13.19.2 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:62545
    P
    libass-devel-0.14.0-1.25 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:63567
    P
    argyllcms-1.9.2-2.27 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:62522
    P
    gnome-online-accounts-devel-3.26.2-3.34 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:2588
    P
    Security update for python-pip (Important)
    2020-12-02
    oval:org.opensuse.security:def:2853
    P
    Security update for jasper (Moderate)
    2020-12-02
    oval:org.opensuse.security:def:2635
    P
    Security update for libopenmpt (Moderate)
    2020-12-02
    oval:org.opensuse.security:def:2620
    P
    Security update for podman (Moderate)
    2020-12-02
    oval:org.opensuse.security:def:2673
    P
    Security update for libnettle (Moderate)
    2020-12-02
    oval:org.opensuse.security:def:2675
    P
    Security update for MozillaFirefox, mozilla-nspr and mozilla-nss (Important)
    2020-12-02
    oval:org.opensuse.security:def:2594
    P
    Security update for cf-cli (Moderate)
    2020-12-02
    oval:org.opensuse.security:def:2659
    P
    Security update for wireshark (Important)
    2020-12-02
    oval:org.opensuse.security:def:68738
    P
    Security update for python-cryptography (Moderate)
    2020-12-02
    oval:org.opensuse.security:def:2626
    P
    Security update for containerd, docker, docker-runc, golang-github-docker-libnetwork (Moderate)
    2020-12-02
    oval:org.opensuse.security:def:2584
    P
    Security update for postgresql10 (Important)
    2020-12-02
    oval:org.opensuse.security:def:2606
    P
    Security update for containerd, docker, docker-runc, go, go1.11, go1.12, golang-github-docker-libnetwork (Important)
    2020-12-02
    oval:org.opensuse.security:def:2665
    P
    Security update for accountsservice (Moderate)
    2020-12-02
    oval:org.opensuse.security:def:49247
    P
    libtspi1 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:64134
    P
    Security update for xerces-c (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:50091
    P
    python3-pywbem on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49867
    P
    xorg-x11-server-sdk on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:64390
    P
    libsystemd0 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:50520
    P
    Security update for samba (Important)
    2020-12-01
    oval:org.opensuse.security:def:49102
    P
    git-core on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:63894
    P
    Security update for apache2 (Important)
    2020-12-01
    oval:org.opensuse.security:def:65404
    P
    Security update for openexr (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49696
    P
    libsrtp-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:50689
    P
    Security update for python3 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49516
    P
    gdk-pixbuf-query-loaders-32bit on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:50360
    P
    Security update for MozillaFirefox, mozilla-nspr and mozilla-nss (Important)
    2020-12-01
    oval:org.opensuse.security:def:49101
    P
    giflib-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:64236
    P
    cyrus-sasl on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:50181
    P
    dia on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:65494
    P
    Security update for xorg-x11-server (Important)
    2020-12-01
    oval:org.opensuse.security:def:49371
    P
    containerd on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49965
    P
    libwsman-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:50347
    P
    Security update for postgresql10 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:64028
    P
    Security update for mozilla-nspr, mozilla-nss (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49370
    P
    zypper on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49853
    P
    pam-devel-32bit on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49721
    P
    wavpack on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:50316
    P
    Security update for libxml2 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:50450
    P
    Security update for qemu (Important)
    2020-12-01
    oval:org.opensuse.security:def:68841
    P
    Security update for go1.12 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:74456
    P
    Security update for go1.12 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49598
    P
    rtkit on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:50616
    P
    Security update for samba (Important)
    2020-12-01
    oval:org.opensuse.security:def:50251
    P
    openconnect on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49389
    P
    accountsservice on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:50122
    P
    nodejs10 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:50420
    P
    Security update for postgresql10 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:50585
    P
    Security update for wicked (Important)
    2020-12-01
    oval:com.redhat.rhsa:def:20200329
    P
    RHSA-2020:0329: go-toolset:rhel8 security update (Moderate)
    2020-02-04
    oval:org.opensuse.security:def:110080
    P
    Security update for go1.12 (Moderate)
    2019-11-17
    oval:org.opensuse.security:def:90860
    P
    Security update for go1.12 (Moderate)
    2019-11-11
    oval:org.opensuse.security:def:97825
    P
    Security update for go1.12 (Moderate)
    2019-11-11
    oval:org.opensuse.security:def:104515
    P
    Security update for go1.12 (Moderate)
    2019-11-11
    oval:com.ubuntu.disco:def:2019175960000000
    V
    CVE-2019-17596 on Ubuntu 19.04 (disco) - medium.
    2019-10-24
    oval:com.ubuntu.bionic:def:2019175960000000
    V
    CVE-2019-17596 on Ubuntu 18.04 LTS (bionic) - medium.
    2019-10-24
    oval:com.ubuntu.xenial:def:2019175960000000
    V
    CVE-2019-17596 on Ubuntu 16.04 LTS (xenial) - medium.
    2019-10-24
    BACK
    golang go *
    golang go *
    debian debian linux 9.0
    debian debian linux 10.0
    fedoraproject fedora 30
    fedoraproject fedora 31
    redhat developer tools 1.0
    redhat enterprise linux 8.0
    redhat enterprise linux server 8.1
    opensuse leap 15.0
    opensuse leap 15.1
    arista cloudvision portal *
    arista cloudvision portal 2019.1.0
    arista cloudvision portal 2019.1.1
    arista cloudvision portal 2019.1.2
    arista terminattr *
    arista eos *
    arista mos *
    golang go 1.12.10
    golang go 1.13.1
    ibm api connect 2018.4.1.0
    ibm cloud private 3.2.0 cd
    ibm cloud private 3.2.1 cd
    ibm api connect 2018.4.1.9
    ibm cloud automation manager 3.2.1.0