Описание
The "go bug" command writes to two files with predictable names in the system temporary directory (for example, "/tmp"). An attacker with access to the temporary directory can create a symlink in one of these names, causing "go bug" to overwrite the target of the symlink.
A flaw was found in the 'go bug' command within the Go programming language tools. This command writes to temporary files with predictable names. A local attacker with access to the system's temporary directory could exploit this by creating a symbolic link (symlink) with one of these predictable names. This would cause the 'go bug' command to overwrite the target of the symlink, potentially leading to arbitrary file overwrite.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Multicluster Engine for Kubernetes | multicluster-engine/addon-manager-rhel9 | Under investigation | ||
| Multicluster Engine for Kubernetes | multicluster-engine/backplane-rhel9-operator | Under investigation | ||
| Multicluster Engine for Kubernetes | multicluster-engine/clusterlifecycle-state-metrics-rhel9 | Under investigation | ||
| Multicluster Engine for Kubernetes | multicluster-engine/hypershift-addon-rhel9-operator | Under investigation | ||
| Multicluster Engine for Kubernetes | multicluster-engine/maestro-rhel9 | Under investigation | ||
| Multicluster Engine for Kubernetes | multicluster-engine/managedcluster-import-controller-rhel9 | Under investigation | ||
| Multicluster Engine for Kubernetes | multicluster-engine/multicloud-manager-rhel9 | Under investigation | ||
| Multicluster Engine for Kubernetes | multicluster-engine/placement-rhel9 | Under investigation | ||
| Multicluster Engine for Kubernetes | multicluster-engine/registration-operator-rhel9 | Under investigation | ||
| Multicluster Engine for Kubernetes | multicluster-engine/work-rhel9 | Under investigation |
Показывать по
Дополнительная информация
Статус:
4.4 Medium
CVSS3
Связанные уязвимости
The "go bug" command writes to two files with predictable names in the system temporary directory (for example, "/tmp"). An attacker with access to the temporary directory can create a symlink in one of these names, causing "go bug" to overwrite the target of the symlink.
The "go bug" command writes to two files with predictable names in the system temporary directory (for example, "/tmp"). An attacker with access to the temporary directory can create a symlink in one of these names, causing "go bug" to overwrite the target of the symlink.
Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
The "go bug" command writes to two files with predictable names in the ...
The "go bug" command writes to two files with predictable names in the system temporary directory (for example, "/tmp"). An attacker with access to the temporary directory can create a symlink in one of these names, causing "go bug" to overwrite the target of the symlink.
4.4 Medium
CVSS3