Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

crypto/elliptic: CPU DoS vulnerability affecting P-521 and P-384 [Go 1.11] #29904

Closed
julieqiu opened this issue Jan 23, 2019 · 1 comment
Closed
Labels
CherryPickApproved Used during the release process for point releases FrozenDueToAge Security
Milestone

Comments

@julieqiu
Copy link
Member

This is tracking #29903.

@julieqiu julieqiu added this to the Go1.11.5 milestone Jan 23, 2019
@julieqiu julieqiu added Security CherryPickApproved Used during the release process for point releases labels Jan 23, 2019
@FiloSottile
Copy link
Contributor

This is fixed by 42b42f7

JohnStarich added a commit to JohnStarich/xgo that referenced this issue Feb 17, 2019
* Add Go 1.11.5 to address security vulnerability golang/go#29904
* Add slim base and go images that exclude iOS and Android
* Add nano base and go images that only include 64-bit Linux and macOS
@golang golang locked and limited conversation to collaborators Jan 23, 2020
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
CherryPickApproved Used during the release process for point releases FrozenDueToAge Security
Projects
None yet
Development

No branches or pull requests

3 participants