Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2025-61731

Опубликовано: 28 янв. 2026
Источник: ubuntu
Приоритет: medium
CVSS3: 7.8

Описание

Building a malicious file with cmd/go can cause can cause a write to an attacker-controlled file with partial control of the file content. The "#cgo pkg-config:" directive in a Go source file provides command-line arguments to provide to the Go pkg-config command. An attacker can provide a "--log-file" argument to this directive, causing pkg-config to write to an attacker-controlled location.

РелизСтатусПримечание
devel

DNE

jammy

DNE

noble

DNE

questing

DNE

resolute

DNE

upstream

needs-triage

Показывать по

РелизСтатусПримечание
devel

DNE

esm-infra-legacy/trusty

needed

esm-infra-legacy/xenial

needed

esm-infra/bionic

needed

esm-infra/xenial

ignored

end of ESM support, was needs-triage
jammy

DNE

noble

DNE

questing

DNE

resolute

DNE

upstream

needs-triage

Показывать по

РелизСтатусПримечание
devel

DNE

esm-apps-legacy/xenial

needed

esm-apps/bionic

needed

esm-apps/jammy

needed

esm-apps/xenial

ignored

end of ESM support, was needs-triage
esm-infra/focal

needed

jammy

needed

noble

DNE

questing

DNE

resolute

DNE

Показывать по

РелизСтатусПримечание
devel

DNE

esm-infra/focal

needed

jammy

DNE

noble

DNE

questing

DNE

resolute

DNE

upstream

needs-triage

Показывать по

РелизСтатусПримечание
devel

DNE

esm-apps/bionic

needed

esm-apps/focal

needed

jammy

DNE

noble

DNE

questing

DNE

resolute

DNE

upstream

needs-triage

Показывать по

РелизСтатусПримечание
devel

DNE

jammy

needed

noble

DNE

questing

DNE

resolute

DNE

upstream

needs-triage

Показывать по

РелизСтатусПримечание
devel

DNE

esm-apps-legacy/xenial

needed

esm-apps/bionic

needed

esm-apps/focal

needed

esm-apps/xenial

ignored

end of ESM support, was needs-triage
jammy

needed

noble

DNE

questing

DNE

resolute

DNE

upstream

needs-triage

Показывать по

РелизСтатусПримечание
devel

DNE

esm-apps/focal

needed

esm-apps/jammy

needed

jammy

needed

noble

DNE

questing

DNE

resolute

DNE

upstream

needs-triage

Показывать по

РелизСтатусПримечание
devel

DNE

esm-apps/focal

needed

esm-apps/jammy

needed

esm-apps/noble

needed

jammy

needed

noble

needed

questing

DNE

resolute

DNE

upstream

needs-triage

Показывать по

РелизСтатусПримечание
devel

DNE

esm-apps/focal

needed

esm-apps/jammy

needed

jammy

needed

noble

needed

questing

DNE

resolute

DNE

upstream

needs-triage

Показывать по

РелизСтатусПримечание
devel

needed

esm-apps/jammy

needed

esm-apps/noble

needed

esm-apps/resolute

needed

jammy

needed

noble

needed

questing

ignored

end of life, was needed
resolute

needed

upstream

needs-triage

Показывать по

РелизСтатусПримечание
devel

needed

esm-apps/jammy

needed

esm-apps/noble

needed

jammy

needed

noble

needed

questing

ignored

end of life, was needed
resolute

needed

upstream

needs-triage

Показывать по

РелизСтатусПримечание
devel

needed

jammy

DNE

noble

DNE

questing

ignored

end of life, was needed
resolute

needed

upstream

needs-triage

Показывать по

РелизСтатусПримечание
devel

DNE

esm-infra-legacy/xenial

not-affected

code not present
esm-infra/xenial

ignored

end of ESM support, was needs-triage
jammy

DNE

noble

DNE

questing

DNE

resolute

DNE

upstream

needs-triage

Показывать по

РелизСтатусПримечание
devel

DNE

esm-apps/bionic

not-affected

code not present
jammy

DNE

noble

DNE

questing

DNE

resolute

DNE

upstream

needs-triage

Показывать по

РелизСтатусПримечание
devel

DNE

esm-apps/bionic

not-affected

code not present
jammy

DNE

noble

DNE

questing

DNE

resolute

DNE

upstream

needs-triage

Показывать по

7.8 High

CVSS3

Связанные уязвимости

CVSS3: 8.6
redhat
7 месяцев назад

Building a malicious file with cmd/go can cause can cause a write to an attacker-controlled file with partial control of the file content. The "#cgo pkg-config:" directive in a Go source file provides command-line arguments to provide to the Go pkg-config command. An attacker can provide a "--log-file" argument to this directive, causing pkg-config to write to an attacker-controlled location.

CVSS3: 7.8
nvd
7 месяцев назад

Building a malicious file with cmd/go can cause can cause a write to an attacker-controlled file with partial control of the file content. The "#cgo pkg-config:" directive in a Go source file provides command-line arguments to provide to the Go pkg-config command. An attacker can provide a "--log-file" argument to this directive, causing pkg-config to write to an attacker-controlled location.

CVSS3: 7.8
debian
7 месяцев назад

Building a malicious file with cmd/go can cause can cause a write to a ...

CVSS3: 7.8
redos
7 месяцев назад

Уязвимость golang

CVSS3: 7.8
github
7 месяцев назад

Building a malicious file with cmd/go can cause can cause a write to an attacker-controlled file with partial control of the file content. The "#cgo pkg-config:" directive in a Go source file provides command-line arguments to provide to the Go pkg-config command. An attacker can provide a "--log-file" argument to this directive, causing pkg-config to write to an attacker-controlled location.

7.8 High

CVSS3

Уязвимость CVE-2025-61731