HomeDefault status
unaffected
Any version before 0.45.0
affected
Description
SSH servers parsing GSSAPI authentication requests do not validate the number of mechanisms specified in the request, allowing an attacker to cause unbounded memory consumption.
Problem types
Product status
Any version before 0.45.0
Credits
Jakub Ciolek
References
groups.google.com/g/golang-announce/c/w-oX3UxNcZA