Risk Scores
EPSS Score
2.70%
85.8th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ubuntu:Pro:16.04:LTS | golang-go.crypto | 1:0.0~git20151201.0.7b85b09-2, 1:0.0~git20151201.0.7b85b09-2ubuntu0.1~esm1, 1:0.0~git20150608-1 |
| Ubuntu:Pro:18.04:LTS | golang-go.crypto | 1:0.0~git20170629.0.5ef0053-2ubuntu0.1~esm1, 1:0.0~git20170629.0.5ef0053-1ubuntu1, 0 |
| Ubuntu:22.04:LTS | snapd | 0, 2.57.5+22.04, 2.57.4+22.04 |
| Ubuntu:24.04:LTS | snapd | 2.72+ubuntu24.04, 2.71+ubuntu24.04, 2.68.5+ubuntu24.04.1 |
| Ubuntu:Pro:16.04:LTS | snapd | 2.54.3+16.04.0ubuntu0.1~esm5, 2.54.3+16.04.0ubuntu0.1~esm6, 2.61.4ubuntu0.16.04.1+esm1 |
| Ubuntu:20.04:LTS | snapd | 2.46.1+20.04, 2.47.1+20.04, 2.48+20.04 |
| Ubuntu:25.10 | snapd | 0, 2.67.1+25.04, 2.68.5+ubuntu25.10.2 |
| Ubuntu:Pro:18.04:LTS | snapd | 2.29.4.2+18.04, 2.61.4ubuntu0.18.04.1+esm1, 2.58+18.04.1 |
Timeline
- May 9, 2019 CVE Published
- Apr 14, 2021 EPSS Score
- Jun 22, 2021 EPSS Score
- Oct 24, 2021 EPSS Score
- Dec 25, 2021 EPSS Score
- Jan 6, 2022 EPSS Score
- Feb 4, 2022 EPSS Score
- Apr 1, 2022 EPSS Score
- Apr 28, 2022 EPSS Score
- Jun 29, 2022 EPSS Score
- Aug 31, 2022 EPSS Score
- Jan 2, 2023 EPSS Score
References
- https://ubuntu.com/security/CVE-2019-11840 third-party-advisory
- https://go.googlesource.com/crypto/+/b7391e95e576cacdcdd422573063bc057239113d third-party-advisory
- https://groups.google.com/forum/#!msg/golang-announce/tjyNcJxb2vQ/n0NRBziSCAAJ third-party-advisory
- https://www.cve.org/CVERecord?id=CVE-2019-11840 third-party-advisory