Advisories ยป MGASA-2018-0238

Updated golang packages fix security vulnerability

Publication date: 16 May 2018
Modification date: 16 May 2018
Type: security
Affected Mageia releases : 6
CVE: CVE-2018-7187

Description

A flaw was found in Go Lang. The "go get" implementation in Go 1.9.4,
when the -insecure command-line option is used, does not validate the
import path (get/vcs.go only checks for "://" anywhere in the string),
which allows remote attackers to execute arbitrary OS commands via a
crafted web site (CVE-2018-7187)
                

References

SRPMS

6/core