FlawAtlas
Search the atlas
CVE-2020-29652 High

CVE-2020-29652

A nil pointer dereference in the golang.org/x/crypto/ssh component through v0.0.0-20201203163018-be400aefbc4c for Go allows remote attackers to cause a denial of service against SSH servers.

Exploit probability 3.2%
Published December 17, 2020
Required by Not available
Last source change March 14, 2026

02 / AFFECTED SOFTWARE

Affected packages

Unknown Unknown
Go golang.org/x/crypto
Go golang.org/x/crypto

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities CVE-2020-29652

A nil pointer dereference in the golang.org/x/crypto/ssh component through v0.0.0-20201203163018-be400aefbc4c for Go allows remote attackers to cause a denial of service against SSH servers.

View original source
Open Source Vulnerabilities GHSA-3vm4-22fp-5rfm

A nil pointer dereference in the golang.org/x/crypto/ssh component through v0.0.0-20201203163018-be400aefbc4c for Go allows remote attackers to cause a denial of service against SSH servers. An attacker can craft an authentication request message for the `gssapi-with-mic` method which will cause NewServerConn to panic via a nil pointer dereference if ServerConfig.GSSAPIWithMICConfig is nil.

View original source
Open Source Vulnerabilities GO-2021-0227

Clients can cause a panic in SSH servers. An attacker can craft an authentication request message for the “gssapi-with-mic” method which will cause NewServerConn to panic via a nil pointer dereference if ServerConfig.GSSAPIWithMICConfig is nil.

View original source

05 / REFERENCES

Further evidence