CVE-2017-8932

medium
Published 2017-07-06 · Modified 2024-05-20
CVSS v3
5.9
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS v2
4.3
VIR risk
5.9

Description

Incorrect computation for P-256 curves in crypto/elliptic

Predictions

Exploit likelihood
69%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: cve@mitre.org — https://groups.google.com/d/msg/golang-announce/B5ww0iFt1_Q/TgUFJV14BgAJ

vendor Authored 2026-05-27

Vendor advisory: cve@mitre.org — https://go-review.googlesource.com/c/41070/

vendor Authored 2026-05-27

Vendor advisory: cve@mitre.org — https://github.com/golang/go/commit/9294fa2749ffee7edbbb817a0ef9fe633136fa9c

vendor Authored 2026-05-27

Vendor advisory: cve@mitre.org — http://lists.opensuse.org/opensuse-updates/2017-06/msg00080.html

vendor Authored 2026-05-27

Vendor advisory: cve@mitre.org — http://lists.opensuse.org/opensuse-updates/2017-06/msg00079.html

OS impact

OSVersionStatusFixed in
suse suse42.2affected
fedora fedora25affected

Package impact

EcosystemPackageVulnerableFixed
golang Gostdlib>=1.8.0-0,<1.8.21.7.6

Application impact

VendorProductVersionsFixed
golanggo{"endIncluding":"1.7.5"}
golanggo1.8
golanggo1.8.1
novellsuse_package_hub_for_suse_linux_enterprise12

References

CWEs

CWE-682

Verify integrity in audit chain (admin only). AS-IS.