First published: Wed Feb 07 2018(Updated: )
Go before 1.8.7, Go 1.9.x before 1.9.4, and Go 1.10 pre-releases before Go 1.10rc2 allow "go get" remote command execution during source code build, by leveraging the gcc or clang plugin feature, because -fplugin= and -plugin= arguments were not blocked.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/go | <1.8.7 | 1.8.7 |
redhat/go | <1.9.4 | 1.9.4 |
redhat/go | <1.10 | 1.10 |
debian/golang | ||
debian/golang-1.10 | ||
debian/golang-1.7 | ||
Golang Go | <=1.8.6 | |
Golang Go | =1.9 | |
Golang Go | =1.9.1 | |
Golang Go | =1.9.2 | |
Golang Go | =1.9.3 | |
Golang Go | =1.10-beta1 | |
Golang Go | =1.10-beta2 | |
Golang Go | =1.10-rc1 | |
Debian Debian Linux | =9.0 | |
Redhat Enterprise Linux Server | =7.0 | |
Redhat Enterprise Linux Server Aus | =7.6 | |
Redhat Enterprise Linux Server Eus | =7.6 | |
Redhat Enterprise Linux Server Tus | =7.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.