CVE-2020-29652
Aliases:GHSA-3vm4-22fp-5rfmGO-2021-0227DEBIAN-CVE-2020-29652CGA-4x4r-2m92-88w3CGA-ff49-x95w-66jjCGA-gpxj-vqxf-2xxxCGA-c72p-5mw9-q64qCGA-rv7p-6jqh-crjvCGA-vw3m-7p27-7rh2CGA-wqjf-v6q4-92vhCGA-x5xr-c8c5-c5v4
Advisory lineage Upstream: 0 Downstream: 4
Modified
Published: 17 Dec 2020, 04:12
Last modified:04 Aug 2024, 16:55
Vulnerability Summary
Overall Risk (default)
medium
31/100 CVSS Score
7.5 HIGH
v3.1 (nvd)
EPSS Score
3.27% LOW
3% probability +3.23%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected
Timeline
17 Dec 2020, 04:12
Published
Vulnerability first disclosed
04 Aug 2024, 16:55
Last Modified
Vulnerability information updated
Description
A nil pointer dereference in the golang.org/x/crypto/ssh component through v0.0.0-20201203163018-be400aefbc4c for Go allows remote attackers to cause a denial of service against SSH servers.
CVSS Metrics
- v3.1•HIGH•Score: 7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- v2.0•MEDIUM•Score: 5AV:N/AC:L/Au:N/C:N/I:N/A:P
EPSS Trends
Current EPSS score: 3.27%• Percentile: 88%
Techniques & Countermeasures
- CWE-476•NULL Pointer Dereference
The product dereferences a pointer that it expects to be valid but is NULL.
Affected Systems
- chainguard•dex-k8s-authenticator
< 0
- chainguard•k3d
< 5.6.0-r11
- chainguard•k3d-proxy
< 5.6.0-r11
- chainguard•k3d-tools
< 5.6.0-r11
- wolfi•k3d
< 5.6.0-r11
- wolfi•k3d-proxy
< 5.6.0-r11
- wolfi•k3d-tools
< 5.6.0-r11
- debian•golang-go.crypto
< 1:0.0~git20201221.eec23a3-1 | < 1:0.0~git20201221.eec23a3-1 | < 1:0.0~git20201221.eec23a3-1 | < 1:0.0~git20201221.eec23a3-1
- golang.org/x•crypto
< 0.0.0-20201216223049-8b5274cf687f
- golang•ssh
≤ 0.0.0-20201203163018-be400aefbc4c
References (9)
- https://groups.google.com/g/golang-announce/c/ouZIlBimOsE?pli=1
- https://go-review.googlesource.com/c/crypto/+/278852
- https://lists.apache.org/thread.html/r68032132c0399c29d6cdc7bd44918535da54060a10a12b1591328bff%40%3Cnotifications.skywalking.apache.org%3E
- https://nvd.nist.gov/vuln/detail/CVE-2020-29652
- https://go.dev/cl/278852
- https://go.googlesource.com/crypto/+/8b5274cf687fd9316b4108863654cc57385531e8
- https://lists.apache.org/thread.html/r68032132c0399c29d6cdc7bd44918535da54060a10a12b1591328bff@%3Cnotifications.skywalking.apache.org%3E
- https://pkg.go.dev/vuln/GO-2021-0227
- https://security-tracker.debian.org/tracker/CVE-2020-29652