Remote code execution in go get, when executed with the -u flag (CVE-2018-16873). An arbitrary filesystem write in go get, which could lead to code execution (CVE-2018-16874). . MGASA-2019-0066 - Updated golang packages fix security vulnerability Publication date: 13 Feb 2019 URL: https://advisories.mageia.org/MGASA-2019-0066.html Type: security Affected Mageia releases: 6 CVE: CVE-2018-16873, CVE-2018-16874, CVE-2018-16875, CVE-2019-6486 Remote code execution in go get, when executed with the -u flag (CVE-2018-16873). An arbitrary filesystem write in go get, which could lead to code execution (CVE-2018-16874). Denial of Service in the crypto/x509 package during certificate chain validation (CVE-2018-16875). Go before 1.11.5 mishandles P-521 and P-384 elliptic curves, which allows attackers to cause a denial of service (CPU consumption) or possibly conduct ECDH private key recovery attacks (CVE-2019-6486). References: - https://bugs.mageia.org/show_bug.cgi?id=24014 - - https://lists.debian.org/debian-security-announce/2019/msg00019.html - https://www.cve.org/CVERecord?id=CVE-2018-16873 - https://www.cve.org/CVERecord?id=CVE-2018-16874 - https://www.cve.org/CVERecord?id=CVE-2018-16875 - https://www.cve.org/CVERecord?id=CVE-2019-6486 SRPMS: - 6/core/golang-1.11.5-1.mga6 . Recent updates to Golang packages in Mageia have addressed serious vulnerabilities, including potential remote code execution and denial of service issues, as of February 2019.. Mageia Security Update, Golang Vulnerability, Remote Code Execution, Denial of Service, Package Update. . LinuxSecurity.com Team
An update that solves three vulnerabilities and has four fixes is now available. Description: Description: This new package for go1.11 fixes the following issues: Security issues fixed: - CVE-2018-16873: Fixed a remote code execution in go get, when executed [More...] with the -u flag (bsc#1118897) with the -u flag (bsc#1118897) [More...] - CVE-2018-16874: Fixed an arbitrary filesystem write in go [More...]. openSUSE Security Update: Security update for go1.11 ______________________________________________________________________________ Announcement ID: openSUSE-SU-2018:4181-1 Rating: important References: #1098017 #1113978 #1118897 #1118898 #1118899 #1119634 #1119706 Cross-References: CVE-2018-16873 CVE-2018-16874 CVE-2018-16875 Affected Products: openSUSE Leap 42.3 openSUSE Leap 15.0 ______________________________________________________________________________ An update that solves three vulnerabilities and has four fixes is now available. Description: This new package for go1.11 fixes the following issues: Security issues fixed: - CVE-2018-16873: Fixed a remote code execution in go get, when executed with the -u flag (bsc#1118897) - CVE-2018-16874: Fixed an arbitrary filesystem write in go get, which could lead to code execution (bsc#1118898) - CVE-2018-16875: Fixed a Denial of Service in the crypto/x509 package during certificate chain validation(bsc#1118899) Non-security issues fixed: - Fixed build error with PIE linker flags on ppc64le (bsc#1113978 bsc#1098017) - Make profile.d/go.sh no longer set GOROOT=, in order to make switching between versions no longer break. This ends up removing the need for go.sh entirely (because GOPATH is also set automatically) (bsc#1119634) The following tracked regression fix is included: - Fix a regression that broke go get for import path patterns containing "..."(bsc#1119706) Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 42.3: zypper in -t patch openSUSE-2018-1572=1 - openSUSE Leap 15.0: zypper in -t patch openSUSE-2018-1572=1 Package List: - openSUSE Leap 42.3 (i586 x86_64): go1.11-1.11.4-2.1 go1.11-doc-1.11.4-2.1 - openSUSE Leap 42.3 (x86_64): go1.11-race-1.11.4-2.1 - openSUSE Leap 15.0 (x86_64): go1.11-1.11.4-lp150.2.1 go1.11-doc-1.11.4-lp150.2.1 go1.11-race-1.11.4-lp150.2.1 References: https://www.suse.com/security/cve/CVE-2018-16873.html https://www.suse.com/security/cve/CVE-2018-16874.html https://www.suse.com/security/cve/CVE-2018-16875.html https://bugzilla.suse.com/1098017 https://bugzilla.suse.com/1113978 https://bugzilla.suse.com/1118897 https://bugzilla.suse.com/1118898 https://bugzilla.suse.com/1118899 https://bugzilla.suse.com/1119634 https://bugzilla.suse.com/1119706 -- . Significant openSUSE upgrade for go1.11 tackles various security vulnerabilities with crucial patches.. go Security Update, openSUSE Patch, go1.11 Exploits, Software Vulnerabilities, openSUSE Security. . Severity: Important. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.