NULL Pointer Dereference Affecting github.com/golang/crypto package, versions <0.0.0-20201216223049-8b5274cf687f


Severity

Recommended
0.0
high
0
10

CVSS assessment made by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.91% (83rd percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about NULL Pointer Dereference vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-GOLANG-GITHUBCOMGOLANGCRYPTO-2825233
  • published9 Jan 2022
  • disclosed9 Jan 2022
  • creditJoern Schneewesiz

Introduced: 9 Jan 2022

CVE-2020-29652  (opens in a new tab)
CWE-476  (opens in a new tab)

How to fix?

Upgrade github.com/golang/crypto to version 0.0.0-20201216223049-8b5274cf687f or higher.

Overview

github.com/golang/crypto is a SSH client and server

Affected versions of this package are vulnerable to NULL Pointer Dereference via a crafted authentication request message for the gssapi-with-mic method which will cause NewServerConn to panic if ServerConfig.GSSAPIWithMICConfig is nil.

CVSS Scores

version 3.1