7.5
CVSSv3

CVE-2021-43565

Published: 06/09/2022 Updated: 07/11/2023
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

The x/crypto/ssh package prior to 0.0.0-20211202192323-5770296d904e of golang.org/x/crypto allows an malicious user to panic an SSH server.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

golang ssh

Vendor Advisories

The x/crypto/ssh package before 000-20211202192323-5770296d904e of golangorg/x/crypto allows an attacker to panic an SSH server (CVE-2021-43565) http2/hpack: avoid quadratic complexity in hpack decoding (CVE-2022-41723) Templates did not properly consider backticks (`) as Javascript string delimiters, and as such didnot escape them as expected ...
The x/crypto/ssh package before 000-20211202192323-5770296d904e of golangorg/x/crypto allows an attacker to panic an SSH server (CVE-2021-43565) A broken cryptographic algorithm flaw was found in golangorg/x/crypto/ssh This issue causes a client to fail authentification with RSA keys to servers that reject signature algorithms based on SHA-2, ...
Synopsis Important: Red Hat OpenShift Data Foundation 4100 RPM security,enhancement&bugfix update Type/Severity Security Advisory: Important Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic Updated images that include numerous enhancements, security, and bug ...
Synopsis Important: Red Hat Advanced Cluster Management 25 security updates, images, and bug fixes Type/Severity Security Advisory: Important Topic Red Hat Advanced Cluster Management for Kubernetes 250 is now generally availableRed Hat Product Security has rated this update as having a security impactof Important A Common Vulnerability ...
Synopsis Low: Release of OpenShift Serverless 1260 Type/Severity Security Advisory: Low Topic Release of OpenShift Serverless 1260The References section contains CVE links providing detailed severity ratingsfor each vulnerability Ratings are based on a Common Vulnerability ScoringSystem (CVSS) base score Description Version 1260 of ...
Synopsis Important: Red Hat OpenShift Data Foundation 4100 enhancement, security & bug fix update Type/Severity Security Advisory: Important Topic Updated images that include numerous enhancements, security, and bug fixesare now available for Red Hat OpenShift Data Foundation 4100 on Red HatEnterprise Linux 8Red Hat Product Security ...
Synopsis Important: Release of containers for OSP 162z director operator tech preview Type/Severity Security Advisory: Important Topic Red Hat OpenStack Platform 162 (Train) director operator containers, with several Important security fixes, are available for technology preview Description Release osp-director-operator imagesSecurity F ...
Synopsis Important: Red Hat OpenShift Service Mesh 209 security update Type/Severity Security Advisory: Important Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic Red Hat OpenShift Service Mesh 209Red Hat Product Security has rated this update as having a secu ...
Synopsis Moderate: Red Hat Advanced Cluster Management 244 security updates and bug fixes Type/Severity Security Advisory: Moderate Topic Red Hat Advanced Cluster Management for Kubernetes 244 GeneralAvailability release images This update provides security fixes, bug fixes, and updates container imagesRed Hat Product Security has rated ...
Synopsis Moderate: Gatekeeper Operator v02 security updates and bug fixes Type/Severity Security Advisory: Moderate Topic Gatekeeper Operator v02Red Hat Product Security has rated this update as having a security impactof Moderate A Common Vulnerability Scoring System (CVSS) base score,which gives a detailed severity rating, is available f ...
Synopsis Moderate: Red Hat Advanced Cluster Management 245 security updates and bug fixes Type/Severity Security Advisory: Moderate Topic Red Hat Advanced Cluster Management for Kubernetes 245 GeneralAvailability release images, which fix bugs and update container imagesRed Hat Product Security has rated this update as having a security ...
Synopsis Moderate: Red Hat Advanced Cluster Management 243 security updates and bug fixes Type/Severity Security Advisory: Moderate Topic Red Hat Advanced Cluster Management for Kubernetes 243 General Availability release images This update provides security fixes, bug fixes, and updates the container imagesRed Hat Product Security has ...
Synopsis Important: Red Hat Advanced Cluster Management 236 security updates and bug fixes Type/Severity Security Advisory: Important Topic Red Hat Advanced Cluster Management for Kubernetes 236 General Availabilityrelease images, which provide security updates and bug fixes Description Red Hat Advanced Cluster Management for Kubernete ...
Synopsis Important: Red Hat Advanced Cluster Management 242 security updates and bug fixes Type/Severity Security Advisory: Important Topic Red Hat Advanced Cluster Management for Kubernetes 242 General Availabilityrelease images This update provides security fixes, fixes bugs, and updates the container imagesRed Hat Product Security ha ...
The x/crypto/ssh package before 000-20211202192323-5770296d904e of golangorg/x/crypto allows an attacker to panic an SSH server (CVE-2021-43565) http2/hpack: avoid quadratic complexity in hpack decoding (CVE-2022-41723) Templates did not properly consider backticks (`) as Javascript string delimiters, and as such didnot escape them as expected ...
The x/crypto/ssh package before 000-20211202192323-5770296d904e of golangorg/x/crypto allows an attacker to panic an SSH server (CVE-2021-43565) A broken cryptographic algorithm flaw was found in golangorg/x/crypto/ssh This issue causes a client to fail authentification with RSA keys to servers that reject signature algorithms based on SHA-2, ...
Version v000-20211202192323-5770296d904e of golangorg/x/crypto fixes a vulnerability in the golangorg/x/crypto/ssh package which allowed unauthenticated clients to cause a panic in SSH servers When using AES-GCM or ChaCha20Poly1305, consuming a malformed packet which contains empty plaintext causes a panic, due to the assumption that there wil ...

Github Repositories

Secure Shell Protocol: Introduction and Some Cryptographic Attacks

Secure Shell Protocol: Introduction and Some Cryptographic Attacks Abstract In this project, we will delve into the world of Secure Shell (SSH), a widely used cryptographic network protocol for secure remote access to systems and secure file transfers We will begin with an introduction to SSH, exploring its key features and benefits We will also discuss the fundamental princi