Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2017-1000097

Опубликовано: 05 окт. 2017
Источник: debian

Описание

On Darwin, user's trust preferences for root certificates were not honored. If the user had a root certificate loaded in their Keychain that was explicitly not trusted, a Go program would still verify a connection using that root certificate.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
golangnot-affectedpackage
golang-1.7not-affectedpackage
golang-1.8not-affectedpackage
golang-1.9not-affectedpackage

Примечания

  • https://github.com/golang/go/issues/18141

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 8 лет назад

On Darwin, user's trust preferences for root certificates were not honored. If the user had a root certificate loaded in their Keychain that was explicitly not trusted, a Go program would still verify a connection using that root certificate.

CVSS3: 4.3
redhat
около 9 лет назад

On Darwin, user's trust preferences for root certificates were not honored. If the user had a root certificate loaded in their Keychain that was explicitly not trusted, a Go program would still verify a connection using that root certificate.

CVSS3: 7.5
nvd
больше 8 лет назад

On Darwin, user's trust preferences for root certificates were not honored. If the user had a root certificate loaded in their Keychain that was explicitly not trusted, a Go program would still verify a connection using that root certificate.

msrc
5 месяцев назад

On Darwin, user's trust preferences for root certificates were not honored. If the user had a root certificate loaded in their Keychain that was explicitly not trusted, a Go program would still verify a connection using that root certificate.

CVSS3: 7.5
github
больше 3 лет назад

On Darwin, user's trust preferences for root certificates were not honored. If the user had a root certificate loaded in their Keychain that was explicitly not trusted, a Go program would still verify a connection using that root certificate.