Anfälligkeitssuche        Suche in 324607 CVE Beschreibungen
und 145615 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.1.10.2021.0018
Kategorie:Mageia Linux Local Security Checks
Titel:Mageia: Security Advisory (MGASA-2021-0018)
Zusammenfassung:The remote host is missing an update for the 'golang' package(s) announced via the MGASA-2021-0018 advisory.
Beschreibung:Summary:
The remote host is missing an update for the 'golang' package(s) announced via the MGASA-2021-0018 advisory.

Vulnerability Insight:
An input validation vulnerability was found in go. From a generated go file
(from the cgo tool) it is possible to modify symbols within that object file
and specify code instead. An attacker could potentially use this flaw by
creating a repository which included malicious pre-built object files that
could execute arbitrary code when downloaded and run via 'go get' or 'go build'
whilst building a go project (CVE-2020-28366).

An input validation vulnerability was found in go. If cgo is specified in a go
file, it is possible to bypass the validation of arguments to the gcc compiler.
An attacker could potentially use this flaw by creating a malicious repository
which would execute arbitrary code when downloaded and run via 'go get' or
'go build' whilst building a go project (CVE-2020-28367).

Affected Software/OS:
'golang' package(s) on Mageia 7.

Solution:
Please install the updated package(s).

CVSS Score:
5.1

CVSS Vector:
AV:N/AC:H/Au:N/C:P/I:P/A:P

Querverweis: Common Vulnerability Exposure (CVE) ID: CVE-2020-28366
https://go.dev/cl/269658
https://go.dev/issue/42559
https://go.googlesource.com/go/+/062e0e5ce6df339dc26732438ad771f73dbf2292
https://groups.google.com/g/golang-announce/c/NpBGTTmKzpM
https://pkg.go.dev/vuln/GO-2022-0475
Common Vulnerability Exposure (CVE) ID: CVE-2020-28367
https://go.dev/cl/267277
https://go.dev/issue/42556
https://go.googlesource.com/go/+/da7aa86917811a571e6634b45a457f918b8e6561
https://lists.debian.org/debian-lts-announce/2023/04/msg00021.html
https://pkg.go.dev/vuln/GO-2022-0476
CopyrightCopyright (C) 2022 Greenbone AG

Dies ist nur einer von 145615 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2025 E-Soft Inc. Alle Rechte vorbehalten.