VDB
BDU%3A2024-11338
BDU%3A2024-11338
PUBLISHED
CVSS 9.399999618530273 CRITICAL
Уязвимость функции ServerConfig.PublicKeyCallback() библиотеки для языка программирования Go crypto, позволяющая нарушителю обойти ограничения безопасности
Risk Scores
CVSS 2.0
9.399999618530273
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| ООО «Ред Софт», АО «ИВК», Сообщество свободного программного обеспечения | РЕД ОС (запись в едином реестре российских программ №3751), АЛЬТ СП 10, crypto |
Timeline
- Jun 20, 2025 CVE Published
- Dec 8, 2025 CVE Updated
References
- http://www.openwall.com/lists/oss-security/2024/12/11/2 url
- https://go.dev/cl/635315 url
- https://go.dev/issue/70779 url
- https://pkg.go.dev/vuln/GO-2024-3321 url
- http://repo.red-soft.ru/redos/7.3c/x86_64/updates url
- https://altsp.su/obnovleniya-bezopasnosti/ url
- https://redos.red-soft.ru/support/secure/uyazvimosti/mnozhestvennye-uyazvimosti-etcd-0312202502/?sphrase_id=1370646 url
- https://github.com/golang/crypto/commit/b4f1988a35dee11ec3e05d6bf3e90b695fbd8909 advisory
- https://groups.google.com/g/golang-announce/c/-nPEi39gI4Q/m/cGVPJCqdAQAJ advisory
- https://go-review.googlesource.com/c/crypto/+/635315 advisory