Unrated severityNVD Advisory· Published Oct 24, 2019· Updated Aug 5, 2024
CVE-2019-17596
CVE-2019-17596
Description
Go before 1.12.11 and 1.3.x before 1.13.2 can panic upon an attempt to process network traffic containing an invalid DSA public key. There are several attack scenarios, such as traffic from a client to a server that verifies client certificates.
Affected products
6- Go/Godescription
- osv-coords5 versionspkg:rpm/opensuse/go1.12&distro=openSUSE%20Leap%2015.0pkg:rpm/opensuse/go1.12&distro=openSUSE%20Leap%2015.1pkg:rpm/opensuse/go1.12&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/go1.13&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/notary&distro=openSUSE%20Tumbleweed
< 1.12.12-lp150.11.1+ 4 more
- (no CPE)range: < 1.12.12-lp150.11.1
- (no CPE)range: < 1.12.12-lp151.2.25.1
- (no CPE)range: < 1.12.17-4.8
- (no CPE)range: < 1.13.15-2.6
- (no CPE)range: < 0.7.0-1.2
Patches
2ef74bfc859c9[release-branch.go1.12-security] go1.12.11
1 file changed · +1 −1
VERSION+1 −1 modified@@ -1 +1 @@ -go1.12.10 \ No newline at end of file +go1.12.11 \ No newline at end of file
72766093e6bd[release-branch.go1.13-security] go1.13.2
1 file changed · +1 −1
VERSION+1 −1 modified@@ -1 +1 @@ -go1.13.1 \ No newline at end of file +go1.13.2 \ No newline at end of file
Vulnerability mechanics
Generated on May 9, 2026. Inputs: CWE entries + fix-commit diffs from this CVE's patches. Citations validated against bundle.
References
13- lists.opensuse.org/opensuse-security-announce/2019-11/msg00043.htmlmitrevendor-advisoryx_refsource_SUSE
- lists.opensuse.org/opensuse-security-announce/2019-11/msg00044.htmlmitrevendor-advisoryx_refsource_SUSE
- access.redhat.com/errata/RHSA-2020:0101mitrevendor-advisoryx_refsource_REDHAT
- access.redhat.com/errata/RHSA-2020:0329mitrevendor-advisoryx_refsource_REDHAT
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/5VS3HPSE25ZSGS4RSOTADC67YNOHIGVV/mitrevendor-advisoryx_refsource_FEDORA
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WVOWGM7IQGRO7DS2MCUMYZRQ4TYOZNAS/mitrevendor-advisoryx_refsource_FEDORA
- www.debian.org/security/2019/dsa-4551mitrevendor-advisoryx_refsource_DEBIAN
- github.com/golang/go/issues/34960mitrex_refsource_CONFIRM
- groups.google.com/d/msg/golang-announce/lVEm7llp0w0/VbafyRkgCgAJmitrex_refsource_CONFIRM
- lists.debian.org/debian-lts-announce/2021/03/msg00014.htmlmitremailing-listx_refsource_MLIST
- lists.debian.org/debian-lts-announce/2021/03/msg00015.htmlmitremailing-listx_refsource_MLIST
- security.netapp.com/advisory/ntap-20191122-0005/mitrex_refsource_CONFIRM
- www.arista.com/en/support/advisories-notices/security-advisories/10134-security-advisory-46mitrex_refsource_MISC
News mentions
0No linked articles in our index yet.