Wind River Support Network

HomeDefectsLIN1018-3201
Fixed

LIN1018-3201 : Security Advisory - go - CVE-2018-16874

Created: Dec 19, 2018    Updated: Feb 2, 2019
Resolved Date: Dec 25, 2018
Found In Version: unknown
Fix Version: 10.18.44.3
Severity: Standard
Applicable for: Wind River Linux LTS 18
Component/s: Userspace

Description

In Go before 1.10.6 and 1.11.x before 1.11.3, the go get command is vulnerable to directory traversal when executed with the import path of a malicious Go package which contains curly braces (both '{' and '}' characters). Specifically, it is only vulnerable in GOPATH mode, but not in module mode (the distinction is documented at https://golang.org/cmd/go/#hdr-Module_aware_go_get). The attacker can cause an arbitrary filesystem write, which can lead to code execution.

https://nvd.nist.gov/vuln/detail/CVE-2018-16874

CVEs


Live chat
Online