UBUNTU-CVE-2022-30629
Non-random values for ticket_age_add in session tickets in crypto/tls before Go 1.17.11 and Go 1.18.3 allow an attacker that can observe TLS handshakes to correlate successive connections by comparing ticket ages during session resumption.
02 / AFFECTED SOFTWARE
Affected packages
1 explicit affected versions
9 explicit affected versions
1 explicit affected versions
1 explicit affected versions
2 explicit affected versions
6 explicit affected versions
6 explicit affected versions
3 explicit affected versions
3 explicit affected versions
1 explicit affected versions
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
Non-random values for ticket_age_add in session tickets in crypto/tls before Go 1.17.11 and Go 1.18.3 allow an attacker that can observe TLS handshakes to correlate successive connections by comparing ticket ages during session resumption.
05 / REFERENCES
Further evidence
- https://github.com/golang/go/commit/c15a8e2dbb5ac376a6ed890735341b812d6b965c
- https://github.com/golang/go/commit/c838098c327a1b6d63446f4722e943b02d235d78
- https://go.dev/issue/52814
- https://groups.google.com/g/golang-announce/c/TzIC9-t8Ytg
- https://ubuntu.com/security/CVE-2022-30629
- https://ubuntu.com/security/notices/USN-6038-1
- https://ubuntu.com/security/notices/USN-6038-2
- https://www.cve.org/CVERecord?id=CVE-2022-30629