Beveiligingsadvies

CVE-2020-28367

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2020-11-18 00:00:00
Laatst bijgewerkt 2024-08-04 16:33:59
Toegewezen door Go
CVSS-score geen score
Status PUBLISHED

Beschrijving

Code injection in the go command with cgo before Go 1.14.12 and Go 1.15.5 allows arbitrary code execution at build time via malicious gcc flags specified via a #cgo directive.