Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2024-24787

Опубликовано: 08 мая 2024
Источник: debian
EPSS Низкий

Описание

On Darwin, building a Go module which contains CGO can trigger arbitrary code execution when using the Apple version of ld, due to usage of the -lto_library flag in a "#cgo LDFLAGS" directive.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
golang-1.22not-affectedpackage
golang-1.21not-affectedpackage
golang-1.19not-affectedpackage
golang-1.15not-affectedpackage
golang-1.11not-affectedpackage

Примечания

  • https://groups.google.com/g/golang-announce/c/wkkO4P9stm0

  • https://github.com/golang/go/issues/67119

EPSS

Процентиль: 85%
0.02478
Низкий

Связанные уязвимости

CVSS3: 6.4
ubuntu
больше 1 года назад

On Darwin, building a Go module which contains CGO can trigger arbitrary code execution when using the Apple version of ld, due to usage of the -lto_library flag in a "#cgo LDFLAGS" directive.

CVSS3: 6.4
nvd
больше 1 года назад

On Darwin, building a Go module which contains CGO can trigger arbitrary code execution when using the Apple version of ld, due to usage of the -lto_library flag in a "#cgo LDFLAGS" directive.

CVSS3: 6.4
msrc
5 месяцев назад

Arbitrary code execution during build on Darwin in cmd/go

suse-cvrf
больше 1 года назад

Security update for go1.21

suse-cvrf
больше 1 года назад

Security update for go1.21

EPSS

Процентиль: 85%
0.02478
Низкий