Alerts This Week
Warning Icon 1 664
Alerts This Week
Warning Icon 1 664

Mageia 6: 2019-0066 Moderate: Golang Remote Code Execution Issues

mageia
Calendar Grey February 13, 2019
Dist Mageia Esm H88
Recent updates to Golang packages in Mageia have addressed serious vulnerabilities, including potential remote code execution and denial of service issues, as of February 2019.
Remote code execution in go get, when executed with the -u flag (CVE-2018-16873)

Summary

Remote code execution in go get, when executed with the -u flag (CVE-2018-16873).
An arbitrary filesystem write in go get, which could lead to code execution (CVE-2018-16874).
Denial of Service in the crypto/x509 package during certificate chain validation (CVE-2018-16875).
Go before 1.11.5 mishandles P-521 and P-384 elliptic curves, which allows attackers to cause a denial of service (CPU consumption) or possibly conduct ECDH private key recovery attacks (CVE-2019-6486).

References

- https://bugs.mageia.org/show_bug.cgi?id=24014

- - https://lists.debian.org/debian-security-announce/2019/msg00019.html

- https://www.cve.org/CVERecord?id=CVE-2018-16873

- https://www.cve.org/CVERecord?id=CVE-2018-16874

- https://www.cve.org/CVERecord?id=CVE-2018-16875

- https://www.cve.org/CVERecord?id=CVE-2019-6486

Resolution

SRPMS

- 6/core/golang-1.11.5-1.mga6

Publication date: 13 Feb 2019
URL: https://advisories.mageia.org/MGASA-2019-0066.html
Type: security
CVE: CVE-2018-16873, CVE-2018-16874, CVE-2018-16875, CVE-2019-6486

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here