First published: Fri Mar 08 2019(Updated: )
Go through 1.12 on Windows misuses certain LoadLibrary functionality, leading to DLL injection.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Go | <1.11.10 | |
Go | >=1.12<1.12.2 | |
Microsoft Windows | ||
All of | ||
Any of | ||
Go | <1.11.10 | |
Go | >=1.12<1.12.2 | |
Microsoft Windows |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-9634 is considered a medium severity vulnerability due to its potential for DLL injection.
To fix CVE-2019-9634, upgrade to Go version 1.12.2 or later.
CVE-2019-9634 affects Go versions prior to 1.12.2 and including versions up to 1.11.10.
CVE-2019-9634 is a DLL injection vulnerability linked to improper use of LoadLibrary functionality on Windows.
Further details about CVE-2019-9634 can be found in security advisories and GitHub issues related to the vulnerability.