6.4
CVSSv2

CVE-2019-6486

Published: 24/01/2019 Updated: 07/11/2023
CVSS v2 Base Score: 6.4 | Impact Score: 4.9 | Exploitability Score: 10
CVSS v3 Base Score: 8.2 | Impact Score: 4.2 | Exploitability Score: 3.9
VMScore: 570
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:P

Vulnerability Summary

Go prior to 1.10.8 and 1.11.x prior to 1.11.5 mishandles P-521 and P-384 elliptic curves, which allows malicious users to cause a denial of service (CPU consumption) or possibly conduct ECDH private key recovery attacks.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

golang go

debian debian linux 8.0

debian debian linux 9.0

opensuse leap 15.0

Vendor Advisories

Debian Bug report logs - #920548 golang-112: CVE-2019-6486 Package: src:golang-112; Maintainer for src:golang-112 is Go Compiler Team <team+go-compiler@trackerdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Sat, 26 Jan 2019 20:09:05 UTC Severity: grave Tags: security, upstream Found in v ...
Go mishandles P-521 and P-384 elliptic curves, which allows attackers to cause a denial of service (CPU consumption) or possibly conduct ECDH private key recovery attacks(CVE-2019-6486) Note: This CVE is also fixed in golang-1113-2amzn202 in the golang111 extras repository ...
Go mishandles P-521 and P-384 elliptic curves, which allows attackers to cause a denial of service (CPU consumption) or possibly conduct ECDH private key recovery attacks (CVE-2019-6486) ...
Go before 1108 and 111x before 1115 mishandles P-521 and P-384 elliptic curves, which allows attackers to cause a denial of service (CPU consumption) or possibly conduct ECDH private key recovery attacks ...
Go before versions 1108 and 1115 has a vulnerability in the crypto/elliptic implementations of the P-521 and P-384 elliptic curves A remote attacker can exploit this by crafting inputs that consume excessive amounts of CPU These inputs might be delivered via TLS handshakes, X509 certificates, JWT tokens, ECDH shares or ECDSA signatures In s ...