Количество 10
Количество 10

CVE-2022-41716
Due to unsanitized NUL values, attackers may be able to maliciously set environment variables on Windows. In syscall.StartProcess and os/exec.Cmd, invalid environment variable values containing NUL values are not properly checked for. A malicious environment variable value can exploit this behavior to set a value for a different environment variable. For example, the environment variable string "A=B\x00C=D" sets the variables "A=B" and "C=D".

CVE-2022-41716
Due to unsanitized NUL values, attackers may be able to maliciously set environment variables on Windows. In syscall.StartProcess and os/exec.Cmd, invalid environment variable values containing NUL values are not properly checked for. A malicious environment variable value can exploit this behavior to set a value for a different environment variable. For example, the environment variable string "A=B\x00C=D" sets the variables "A=B" and "C=D".
CVE-2022-41716
Due to unsanitized NUL values, attackers may be able to maliciously se ...

SUSE-SU-2022:4055-1
Security update for go1.18

SUSE-SU-2022:4054-1
Security update for go1.19
GHSA-mh68-qf2j-8c5g
Due to unsanitized NUL values, attackers may be able to maliciously set environment variables on Windows. In syscall.StartProcess and os/exec.Cmd, invalid environment variable values containing NUL values are not properly checked for. A malicious environment variable value can exploit this behavior to set a value for a different environment variable. For example, the environment variable string "A=B\x00C=D" sets the variables "A=B" and "C=D".

BDU:2023-00266
Уязвимость языка программирования Go, связанная с неверной нейтрализация особых элементов в выходных данных, позволяющая нарушителю установить произвольные переменные среды в Windows
ELSA-2023-18908
ELSA-2023-18908: ol8addon security update (IMPORTANT)
ELSA-2022-24267
ELSA-2022-24267: ol8addon security update (IMPORTANT)

SUSE-SU-2023:2312-1
Security update for go1.18-openssl
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
---|---|---|---|---|
![]() | CVE-2022-41716 Due to unsanitized NUL values, attackers may be able to maliciously set environment variables on Windows. In syscall.StartProcess and os/exec.Cmd, invalid environment variable values containing NUL values are not properly checked for. A malicious environment variable value can exploit this behavior to set a value for a different environment variable. For example, the environment variable string "A=B\x00C=D" sets the variables "A=B" and "C=D". | CVSS3: 7.5 | 0% Низкий | больше 2 лет назад |
![]() | CVE-2022-41716 Due to unsanitized NUL values, attackers may be able to maliciously set environment variables on Windows. In syscall.StartProcess and os/exec.Cmd, invalid environment variable values containing NUL values are not properly checked for. A malicious environment variable value can exploit this behavior to set a value for a different environment variable. For example, the environment variable string "A=B\x00C=D" sets the variables "A=B" and "C=D". | CVSS3: 7.5 | 0% Низкий | больше 2 лет назад |
CVE-2022-41716 Due to unsanitized NUL values, attackers may be able to maliciously se ... | CVSS3: 7.5 | 0% Низкий | больше 2 лет назад | |
![]() | SUSE-SU-2022:4055-1 Security update for go1.18 | 0% Низкий | больше 2 лет назад | |
![]() | SUSE-SU-2022:4054-1 Security update for go1.19 | 0% Низкий | больше 2 лет назад | |
GHSA-mh68-qf2j-8c5g Due to unsanitized NUL values, attackers may be able to maliciously set environment variables on Windows. In syscall.StartProcess and os/exec.Cmd, invalid environment variable values containing NUL values are not properly checked for. A malicious environment variable value can exploit this behavior to set a value for a different environment variable. For example, the environment variable string "A=B\x00C=D" sets the variables "A=B" and "C=D". | CVSS3: 7.5 | 0% Низкий | больше 2 лет назад | |
![]() | BDU:2023-00266 Уязвимость языка программирования Go, связанная с неверной нейтрализация особых элементов в выходных данных, позволяющая нарушителю установить произвольные переменные среды в Windows | CVSS3: 7.5 | 0% Низкий | больше 2 лет назад |
ELSA-2023-18908 ELSA-2023-18908: ol8addon security update (IMPORTANT) | больше 2 лет назад | |||
ELSA-2022-24267 ELSA-2022-24267: ol8addon security update (IMPORTANT) | больше 2 лет назад | |||
![]() | SUSE-SU-2023:2312-1 Security update for go1.18-openssl | около 2 лет назад |
Уязвимостей на страницу