High severity7.5NVD Advisory· Published Oct 24, 2019· Updated Jun 17, 2026
CVE-2019-17596
CVE-2019-17596
Description
Go before 1.12.11 and 1.3.x before 1.13.2 can panic upon an attempt to process network traffic containing an invalid DSA public key. There are several attack scenarios, such as traffic from a client to a server that verifies client certificates.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
24cpe:2.3:a:arista:cloudvision_portal:*:*:*:*:*:*:*:*+ 3 more
- cpe:2.3:a:arista:cloudvision_portal:*:*:*:*:*:*:*:*range: >=2018.1.0,<=2018.2.3
- cpe:2.3:a:arista:cloudvision_portal:2019.1.0:*:*:*:*:*:*:*
- cpe:2.3:a:arista:cloudvision_portal:2019.1.1:*:*:*:*:*:*:*
- cpe:2.3:a:arista:cloudvision_portal:2019.1.2:*:*:*:*:*:*:*
- cpe:2.3:a:redhat:developer_tools:1.0:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:30:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:fedoraproject:fedora:30:*:*:*:*:*:*:*
- cpe:2.3:o:fedoraproject:fedora:31:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux_server:8.1:*:*:*:*:*:*:*
- Go/Godescription
- osv-coords5 versionspkg:rpm/opensuse/go1.12&distro=openSUSE%20Leap%2015.0pkg:rpm/opensuse/go1.12&distro=openSUSE%20Leap%2015.1pkg:rpm/opensuse/go1.12&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/go1.13&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/notary&distro=openSUSE%20Tumbleweed
< 1.12.12-lp150.11.1+ 4 more
- (no CPE)range: < 1.12.12-lp150.11.1
- (no CPE)range: < 1.12.12-lp151.2.25.1
- (no CPE)range: < 1.12.17-4.8
- (no CPE)range: < 1.13.15-2.6
- (no CPE)range: < 0.7.0-1.2
Patches
Vulnerability mechanics
References
13- github.com/golang/go/issues/34960nvdExploitIssue TrackingPatchThird Party Advisory
- lists.opensuse.org/opensuse-security-announce/2019-11/msg00043.htmlnvdMailing ListThird Party Advisory
- lists.opensuse.org/opensuse-security-announce/2019-11/msg00044.htmlnvdMailing ListThird Party Advisory
- access.redhat.com/errata/RHSA-2020:0101nvdThird Party Advisory
- access.redhat.com/errata/RHSA-2020:0329nvdThird Party Advisory
- groups.google.com/d/msg/golang-announce/lVEm7llp0w0/VbafyRkgCgAJnvdRelease NotesThird Party Advisory
- lists.debian.org/debian-lts-announce/2021/03/msg00014.htmlnvdMailing ListThird Party Advisory
- lists.debian.org/debian-lts-announce/2021/03/msg00015.htmlnvdMailing ListThird Party Advisory
- security.netapp.com/advisory/ntap-20191122-0005/nvdThird Party Advisory
- www.arista.com/en/support/advisories-notices/security-advisories/10134-security-advisory-46nvdThird Party Advisory
- www.debian.org/security/2019/dsa-4551nvdThird Party Advisory
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/5VS3HPSE25ZSGS4RSOTADC67YNOHIGVV/nvd
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WVOWGM7IQGRO7DS2MCUMYZRQ4TYOZNAS/nvd
News mentions
0No linked articles in our index yet.