CVE-2020-28367

Publication date

2020-11-18 00:00:00

Family

Go

State

PUBLISHED

Description

Code injection in the go command with cgo before Go 1.14.12 and Go 1.15.5 allows arbitrary code execution at build time via malicious gcc flags specified via a #cgo directive.