CVE-2021-3114

Aliases:GO-2021-0235BIT-golang-2021-3114
Advisory lineage Upstream: 0 Downstream: 24
Modified
Published: 26 Jan 2021, 02:23
Last modified:03 Aug 2024, 16:45

Vulnerability Summary

Overall Risk (default)
medium
26/100
CVSS Score
6.5 MEDIUM
v3.1 (nvd)
EPSS Score
0.12% LOW
0% probability +0.08%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

26 Jan 2021, 02:23
Published
Vulnerability first disclosed
03 Aug 2024, 16:45
Last Modified
Vulnerability information updated

Description

In Go before 1.14.14 and 1.15.x before 1.15.7, crypto/elliptic/p224.go can generate incorrect outputs, related to an underflow of the lowest limb during the final complete reduction in the P-224 field.

CVSS Metrics

  • v3.1MEDIUMScore: 6.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
  • v2.0MEDIUMScore: 6.4AV:N/AC:L/Au:N/C:P/I:P/A:N

EPSS Trends

Current EPSS score: 0.12% Percentile: 31%

Techniques & Countermeasures

  • CWE-682Incorrect Calculation

    The product performs a calculation that generates incorrect or unintended results that are later used in security-critical decisions or resource management.

Affected Systems

  • debiandebian_linux

    9.0 | 10.0

  • fedoraprojectfedora

    33

  • golanggo

    < 1.14.14 | ≥ 1.15, < 1.15.7

  • Gostdlib

    ≥ 1.15.0-0, < 1.15.7

  • netappcloud_insights_telegraf_agent

    na

  • netappstoragegrid

    na

References (11)