MGASA-2018-0144

Source
https://advisories.mageia.org/MGASA-2018-0144.html
Import Source
https://advisories.mageia.org/MGASA-2018-0144.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2018-0144
Related
Published
2018-02-26T16:23:22Z
Modified
2018-02-26T15:54:55Z
Summary
Updated golang packages fix security vulnerability
Details

Updated golang packages fix security vulnerabilities:

Go before 1.9.4 allows "go get" remote command execution during source code build, by leveraging the gcc or clang plugin feature, because -fplugin= and -plugin= arguments were not blocked (CVE-2018-6574).

References
Credits

Affected packages

Mageia:6 / golang

Package

Name
golang
Purl
pkg:rpm/mageia/golang?distro=mageia-6

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.9.4-3.mga6

Ecosystem specific

{
    "section": "core"
}