V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsProductsVendorsDocs
CVE-2019-11841
DEB
Medium

A message-forgery issue was discovered in crypto/openpgp/clearsign/clearsign.go in supplementary Go cryptography libraries 2019-03-25. Acco…

CVSS
5.9
Medium
EPSS
0.02
p73
Published
2019-01-01
Updated
2019-01-01
Description

A message-forgery issue was discovered in crypto/openpgp/clearsign/clearsign.go in supplementary Go cryptography libraries 2019-03-25. According to the OpenPGP Message Format specification in RFC 4880 chapter 7, a cleartext signed message can contain one or more optional "Hash" Armor Headers. The "Hash" Armor Header specifies the message digest algorithm(s) used for the signature. However, the Go clearsign package ignores the value of this header, which allows an attacker to spoof it. Consequently, an attacker can lead a victim to believe the signature was generated using a different message digest algorithm than what was actually used. Moreover, since the library skips Armor Header parsing in general, an attacker can not only embed arbitrary Armor Headers, but also prepend arbitrary text to cleartext messages without invalidating the signatures.

Tags · CWE
Pre-auth
CWE-347
CAPEC-463
CAPEC-475
Affected products
Golang-go.cryptoGolang-go.cryptoGolang-go.cryptoGolang-go.cryptoGolang-go.cryptoGolang-go.cryptoGolang-go.cryptoGolang-go.cryptoGolang-go.cryptoGolang-go.cryptoGolang-go.cryptoGolang-go.cryptoGolang-go.cryptoGolang-go.cryptoGolang-go.cryptoGolang-go.cryptoGolang-go.cryptoGolang-go.cryptoSnapdSnapd
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
Timeline
2019-01-01
Published
2019-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: H
High (H)
Privileges Required
PR: N
None (N)
User Interaction
UI: N
None (N)
Scope
S: U
Unchanged (U)
Confidentiality Impact
C: N
None (N)
Integrity Impact
I: H
High (H)
Availability Impact
A: N
None (N)
Exploit indicators
EPSS
0.016 · p73
Known exploited (KEV)
No
Known exploits — Сканер-ВС
No Сканер-ВС checks registered for this vulnerability yet.
Affected products
ProductVendorStatus
golang-go.cryptoTracked
golang-go.cryptoTracked
golang-go.cryptoTracked
golang-go.cryptoTracked
golang-go.cryptoTracked
golang-go.cryptoTracked
golang-go.cryptoTracked
golang-go.cryptoTracked
golang-go.cryptoTracked
golang-go.cryptoTracked
golang-go.cryptoTracked
golang-go.cryptoTracked
golang-go.cryptoTracked
golang-go.cryptoTracked
golang-go.cryptoTracked
golang-go.cryptoTracked
golang-go.cryptoTracked
golang-go.cryptoTracked
snapdTracked
snapdTracked
Showing first 20 of 37
Source databases
DEB
CVE
UBU