Candidate: CVE-2016-9123 PublicDate: 2017-03-28 02:59:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-9123 http://www.openwall.com/lists/oss-security/2016/11/03/1 https://github.com/square/go-jose/commit/789a4c4bd4c118f7564954f441b29c153ccd6a96 https://hackerone.com/reports/165170 Description: go-jose before 1.0.5 suffers from a CBC-HMAC integer overflow on 32-bit architectures. An integer overflow could lead to authentication bypass for CBC-HMAC encrypted ciphertexts on 32-bit architectures. Ubuntu-Description: Notes: Bugs: Priority: medium Discovered-by: Quan Nguyen Assigned-to: CVSS: nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N [7.5 HIGH] Patches_golang-gopkg-square-go-jose.v1: upstream_golang-gopkg-square-go-jose.v1: released (1.0.5-1) precise_golang-gopkg-square-go-jose.v1: DNE precise/esm_golang-gopkg-square-go-jose.v1: DNE trusty_golang-gopkg-square-go-jose.v1: DNE trusty/esm_golang-gopkg-square-go-jose.v1: DNE vivid/stable-phone-overlay_golang-gopkg-square-go-jose.v1: DNE vivid/ubuntu-core_golang-gopkg-square-go-jose.v1: DNE xenial_golang-gopkg-square-go-jose.v1: DNE yakkety_golang-gopkg-square-go-jose.v1: ignored (reached end-of-life) zesty_golang-gopkg-square-go-jose.v1: not-affected (1.1.0-3) devel_golang-gopkg-square-go-jose.v1: not-affected (1.1.0-3)