CVE-2021-43565

Public on 2022-09-06
Modified on 2024-02-07
Description
The x/crypto/ssh package before 0.0.0-20211202192323-5770296d904e of golang.org/x/crypto allows an attacker to panic an SSH server.
Severity
Important severity
Important
CVSS v3 Base Score
7.5
See breakdown

Affected Packages

Platform Package Release Date Advisory Status
Amazon Linux 1 amazon-ssm-agent 2023-08-30 ALAS-2023-1825 Fixed
Amazon Linux 1 amazon-ssm-agent 2023-10-12 ALAS-2023-1866 Fixed
Amazon Linux 2 - Core amazon-ssm-agent 2023-08-31 ALAS2-2023-2238 Fixed
Amazon Linux 2 - Core amazon-ssm-agent 2023-10-12 ALAS2-2023-2303 Fixed
Amazon Linux 2023 amazon-ssm-agent 2023-08-31 ALAS2023-2023-339 Fixed
Amazon Linux 2023 amazon-ssm-agent 2023-10-12 ALAS2023-2023-388 Fixed

CVSS Scores

Score Type Score Vector
Amazon Linux CVSSv3 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
NVD CVSSv3 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H