ssh: return an error for malformed ed25519 public keys rather than panic

An attacker can craft an ssh-ed25519 or
public key, such that the library will panic when trying to verify a
signature with it. Clients can deliver such a public key and signature
to any server with a PublicKeyCallback, and
servers can deliver them to any client.

This issue was discovered and reported by Alex Gaynor, Fish in a Barrel,
and is tracked as CVE-2020-9283.

1 file changed
Go Cryptography

This repository holds supplementary Go cryptography libraries.


