Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2020-28367

Опубликовано: 18 нояб. 2020
Источник: debian

Описание

Code injection in the go command with cgo before Go 1.14.12 and Go 1.15.5 allows arbitrary code execution at build time via malicious gcc flags specified via a #cgo directive.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
golang-1.15fixed1.15.5-1package
golang-1.11removedpackage
golang-1.8removedpackage
golang-1.7removedpackage
golang-1.7ignoredstretchpackage

Примечания

  • https://groups.google.com/g/golang-announce/c/NpBGTTmKzpM/m/fLguyiM2CAAJ

  • https://github.com/golang/go/issues/42556

  • Fixed by: https://github.com/golang/go/commit/da7aa86917811a571e6634b45a457f918b8e6561 (go1.16beta1)

  • Regression: https://github.com/golang/go/commit/782cf560db4c919790fdb476d1bbe18e5ddf5ffd (go1.16beta1)

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 5 лет назад

Code injection in the go command with cgo before Go 1.14.12 and Go 1.15.5 allows arbitrary code execution at build time via malicious gcc flags specified via a #cgo directive.

CVSS3: 7.5
redhat
около 5 лет назад

Code injection in the go command with cgo before Go 1.14.12 and Go 1.15.5 allows arbitrary code execution at build time via malicious gcc flags specified via a #cgo directive.

CVSS3: 7.5
nvd
около 5 лет назад

Code injection in the go command with cgo before Go 1.14.12 and Go 1.15.5 allows arbitrary code execution at build time via malicious gcc flags specified via a #cgo directive.

CVSS3: 7.5
msrc
около 5 лет назад

Описание отсутствует

CVSS3: 7.5
github
больше 3 лет назад

Go before 1.14.12 and 1.15.x before 1.15.5 allows Argument Injection.