THREATOPS
THREAT OPSThreat News › [NVD] CVE-2024-9355 (MEDIUM 6.5) — A vulnerability was found in Golang FIPS OpenSSL. This flaw allows a malicious user to randomly cause an uninitialized buffer length variable with a zeroed buffer to be returned in FIPS mode. It may also be possible to force a false positive match between non-equal hashes when co

[NVD] CVE-2024-9355 (MEDIUM 6.5) — A vulnerability was found in Golang FIPS OpenSSL. This flaw allows a malicious user to randomly cause an uninitialized buffer length variable with a zeroed buffer to be returned in FIPS mode. It may also be possible to force a false positive match between non-equal hashes when co

lownvdPublished 2024-10-01

CVE-2024-9355 CVSS: 6.5 MEDIUM Published: 2024-10-01T19:15:09.793

A vulnerability was found in Golang FIPS OpenSSL. This flaw allows a malicious user to randomly cause an uninitialized buffer length variable with a zeroed buffer to be returned in FIPS mode. It may also be possible to force a false positive match between non-equal hashes when comparing a trusted computed hmac sum to an untrusted i

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2024-9355