CVE-2019-9634: High severity golang vulnerability
Published Mar 8, 2019
·Updated
Go through 1.12 on Windows misuses certain LoadLibrary functionality, leading to DLL injection.
Affected Software
6 affected components
All of the following
Any of the following
golang Go<1.11.10
golang Go>=1.12<1.12.2
Microsoft Windows
golang Go<1.11.10
golang Go>=1.12<1.12.2
Microsoft Windows
Remediation
Patch Available
Event History
Mar 8, 2019
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Data Sourced
via NVD·03:29 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2019-9634?
CVE-2019-9634 is considered a medium severity vulnerability due to its potential for DLL injection.
2
How do I fix CVE-2019-9634?
To fix CVE-2019-9634, upgrade to Go version 1.12.2 or later.
3
Which versions of Go are affected by CVE-2019-9634?
CVE-2019-9634 affects Go versions prior to 1.12.2 and including versions up to 1.11.10.
4
What type of vulnerability is CVE-2019-9634?
CVE-2019-9634 is a DLL injection vulnerability linked to improper use of LoadLibrary functionality on Windows.
5
Where can I find more information about CVE-2019-9634?
Further details about CVE-2019-9634 can be found in security advisories and GitHub issues related to the vulnerability.