Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2020-28366

Опубликовано: 18 нояб. 2020
Источник: debian
EPSS Низкий

Описание

Code injection in the go command with cgo before Go 1.14.12 and Go 1.15.5 allows arbitrary code execution at build time via a malicious unquoted symbol name in a linked object file.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
golang-1.15fixed1.15.5-1package
golang-1.11removedpackage
golang-1.11postponedbusterpackage
golang-1.8removedpackage
golang-1.8ignoredstretchpackage
golang-1.7removedpackage
golang-1.7ignoredstretchpackage

Примечания

  • https://groups.google.com/g/golang-announce/c/NpBGTTmKzpM/m/fLguyiM2CAAJ

  • https://github.com/golang/go/issues/42559

EPSS

Процентиль: 38%
0.00167
Низкий

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 5 лет назад

Code injection in the go command with cgo before Go 1.14.12 and Go 1.15.5 allows arbitrary code execution at build time via a malicious unquoted symbol name in a linked object file.

CVSS3: 7.5
redhat
около 5 лет назад

Code injection in the go command with cgo before Go 1.14.12 and Go 1.15.5 allows arbitrary code execution at build time via a malicious unquoted symbol name in a linked object file.

CVSS3: 7.5
nvd
около 5 лет назад

Code injection in the go command with cgo before Go 1.14.12 and Go 1.15.5 allows arbitrary code execution at build time via a malicious unquoted symbol name in a linked object file.

CVSS3: 7.5
msrc
около 5 лет назад

Описание отсутствует

CVSS3: 7.5
github
больше 3 лет назад

Go before 1.14.12 and 1.15.x before 1.15.5 allows Code Injection.

EPSS

Процентиль: 38%
0.00167
Низкий