6.4
CVSSv2

CVE-2021-3114

Published: 26/01/2021 Updated: 07/11/2023
CVSS v2 Base Score: 6.4 | Impact Score: 4.9 | Exploitability Score: 10
CVSS v3 Base Score: 6.5 | Impact Score: 2.5 | Exploitability Score: 3.9
VMScore: 570
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:N

Vulnerability Summary

In Go prior to 1.14.14 and 1.15.x prior to 1.15.7, crypto/elliptic/p224.go can generate incorrect outputs, related to an underflow of the lowest limb during the final complete reduction in the P-224 field.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

golang go

fedoraproject fedora 33

debian debian linux 9.0

debian debian linux 10.0

netapp storagegrid -

netapp cloud insights telegraf agent -

Vendor Advisories

Synopsis Moderate: OpenShift Container Storage 311z security and bug fix update Type/Severity Security Advisory: Moderate Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic Updated container images that fix various bugs are now available for Red Hat OpenShift Conta ...
Synopsis Important: OpenShift Container Platform 41030 bug fix and security update Type/Severity Security Advisory: Important Topic Red Hat OpenShift Container Platform release 41030 is now available withupdates to packages and images that fix several bugs and add enhancementsThis release includes a security update for Red Hat OpenShift ...
Multiple security issues were discovered in the implementation of the Go programming language, which could result in denial of service and the P-224 curve implementation could generate incorrect outputs For the stable distribution (buster), these problems have been fixed in version 1116-1+deb10u4 We recommend that you upgrade your golang-111 p ...
In Go before 11414 and 115x before 1157, crypto/elliptic/p224go can generate incorrect outputs, related to an underflow of the lowest limb during the final complete reduction in the P-224 field (CVE-2021-3114) Go before 11414 and 115x before 1157 on Windows is vulnerable to Command Injection and remote code execution when using the "g ...
A security issue was found in Go and fixed in versions 1157 and 11414 The P224() Curve implementation can in rare circumstances generate incorrect outputs, including returning invalid points from ScalarMult The crypto/x509 and golangorg/x/crypto/ocsp (but not crypto/tls) packages support P-224 ECDSA keys, but they are not supported by public ...

Github Repositories

A tool to analyse the list of detected CVEs in the containers (usually created by static security scanner) and compare them to the Red Hat Security Data.

cve-analyser A tool to analyse the list of detected CVEs in the containers (usually created by security scanner like JFrog, Aqua, Sysdig or similar) and compare them to the Red Hat Security Data The cve-analyser can find fixes in the rpm packages bundled in the specified container, as well as the fixes in the non-rpm content (like nodejs libraries) Usage To use this tool just