Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

rocky логотип

RLSA-2025:13935

Опубликовано: 04 окт. 2025
Источник: rocky
Оценка: Important

Описание

Important: golang security update

The golang packages provide the Go programming language compiler.

Security Fix(es):

  • cmd/go: Go VCS Command Execution Vulnerability (CVE-2025-4674)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Затронутые продукты

  • Rocky Linux 9

НаименованиеАрхитектураРелизRPM
golangx86_641.el9_6golang-1.24.6-1.el9_6.x86_64.rpm
golang-binx86_641.el9_6golang-bin-1.24.6-1.el9_6.x86_64.rpm
golang-docsnoarch1.el9_6golang-docs-1.24.6-1.el9_6.noarch.rpm
golang-docsnoarch1.el9_6golang-docs-1.24.6-1.el9_6.noarch.rpm
golang-docsnoarch1.el9_6golang-docs-1.24.6-1.el9_6.noarch.rpm
golang-docsnoarch1.el9_6golang-docs-1.24.6-1.el9_6.noarch.rpm
golang-miscnoarch1.el9_6golang-misc-1.24.6-1.el9_6.noarch.rpm
golang-miscnoarch1.el9_6golang-misc-1.24.6-1.el9_6.noarch.rpm
golang-miscnoarch1.el9_6golang-misc-1.24.6-1.el9_6.noarch.rpm
golang-miscnoarch1.el9_6golang-misc-1.24.6-1.el9_6.noarch.rpm

Показывать по

Связанные CVE

Исправления

Связанные уязвимости

CVSS3: 8.6
ubuntu
6 месяцев назад

The go command may execute unexpected commands when operating in untrusted VCS repositories. This occurs when possibly dangerous VCS configuration is present in repositories. This can happen when a repository was fetched via one VCS (e.g. Git), but contains metadata for another VCS (e.g. Mercurial). Modules which are retrieved using the go command line, i.e. via "go get", are not affected.

CVSS3: 8.6
redhat
6 месяцев назад

The go command may execute unexpected commands when operating in untrusted VCS repositories. This occurs when possibly dangerous VCS configuration is present in repositories. This can happen when a repository was fetched via one VCS (e.g. Git), but contains metadata for another VCS (e.g. Mercurial). Modules which are retrieved using the go command line, i.e. via "go get", are not affected.

CVSS3: 8.6
nvd
6 месяцев назад

The go command may execute unexpected commands when operating in untrusted VCS repositories. This occurs when possibly dangerous VCS configuration is present in repositories. This can happen when a repository was fetched via one VCS (e.g. Git), but contains metadata for another VCS (e.g. Mercurial). Modules which are retrieved using the go command line, i.e. via "go get", are not affected.

CVSS3: 8.6
msrc
5 месяцев назад

Unexpected command execution in untrusted VCS repositories in cmd/go

CVSS3: 8.6
debian
6 месяцев назад

The go command may execute unexpected commands when operating in untru ...