[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248678

 
 

909

 
 

195426

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

ALAS-2018-975

ID: oval:org.secpod.oval:def:1600859Date: (C)2018-04-02   (M)2023-11-10
Class: PATCHFamily: unix




Arbitrary code execution during "go get" via C compiler options:An arbitrary command execution flaw was found in the way Go#039;s go get command handled gcc and clang sensitive options during the build. A remote attacker capable of hosting malicious repositories could potentially use this flaw to cause arbitrary command execution on the client side

Platform:
Amazon Linux AMI
Product:
golang
Reference:
ALAS-2018-975
CVE-2018-7187
CVE-2018-6574
CVE    2
CVE-2018-6574
CVE-2018-7187
CPE    2
cpe:/o:amazon:linux
cpe:/a:golang:golang

© SecPod Technologies