DescriptionThe Int.Exp Montgomery code in the math/big library in Go 1.5.x before 1.5.3 mishandles carry propagation and produces incorrect output, which makes it easier for attackers to obtain private RSA keys via unspecified vectors.
NVD severitymedium
Debian Bugs809168

golangsourcewheezy(not affected)
golangsourcejessie(not affected)


[jessie] - golang <not-affected> (Introduced in 1.5 release)
[wheezy] - golang <not-affected> (Introduced in 1.5 release)
Introduced in 1.5 release. Fixed in 1.5.3 upstream.

