Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
From golang/go#29233 Package crypto/x509 parses and validates X.509-encoded keys and certificates. It's supposed to handle certificate chains provided by an attacker with reasonable resource use. The crypto/x509 package does not limit the amount of work performed for each chain verification, which might allow attackers to craft pathological inputs leading to a CPU denial of service. Go TLS servers accepting client certificates and TLS clients verifying certificates are affected. Go 1.11.3 and 1.10.6 have been released with this fixed.
- Loading branch information