8.1

CVE-2018-16873

In Go before 1.10.6 and 1.11.x before 1.11.3, the "go get" command is vulnerable to remote code execution when executed with the -u flag and the import path of a malicious Go package, or a package that imports it directly or indirectly. Specifically, it is only vulnerable in GOPATH mode, but not in module mode (the distinction is documented at https://golang.org/cmd/go/#hdr-Module_aware_go_get). Using custom domains, it's possible to arrange things so that a Git repository is cloned to a folder named ".git" by using a vanity import path that ends with "/.git". If the Git repository root contains a "HEAD" file, a "config" file, an "objects" directory, a "refs" directory, with some work to ensure the proper ordering of operations, "go get -u" can be tricked into considering the parent directory as a repository root, and running Git commands on it. That will use the "config" file in the original Git repository root for its configuration, and if that config file contains malicious commands, they will execute on the system running "go get -u".
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Golang ≫ Go Version < 1.10.6
Golang ≫ Go Version >= 1.11.0 < 1.11.3
Opensuse ≫ Backports Sle Version 15.0 Update -
Opensuse ≫ Leap Version 15.0
Opensuse ≫ Leap Version 15.1
Opensuse ≫ Leap Version 42.3
Suse ≫ Linux Enterprise Server Version 12 Update -
Debian ≫ Debian Linux Version 9.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 66.25% 0.992
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 8.1 2.2 5.9
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
NIST 6.8 8.6 6.4
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat 7.5 1.6 5.9
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

http://lists.opensuse.org/opensuse-security-announce/2020-04/msg00041.html
Third Party Advisory
Mailing List
https://lists.debian.org/debian-lts-announce/2021/03/msg00014.html
Third Party Advisory
Mailing List
https://lists.debian.org/debian-lts-announce/2021/03/msg00015.html
Third Party Advisory
Mailing List
http://lists.opensuse.org/opensuse-security-announce/2019-03/msg00044.html
Third Party Advisory
Mailing List
http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00060.html
Third Party Advisory
Mailing List
http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00011.html
Third Party Advisory
Mailing List
http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00015.html
Third Party Advisory
Mailing List
http://lists.opensuse.org/opensuse-security-announce/2019-07/msg00010.html
Third Party Advisory
Mailing List
http://www.securityfocus.com/bid/106226
Third Party Advisory
VDB Entry
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-16873
Third Party Advisory
Issue Tracking
https://groups.google.com/forum/?pli=1#%21topic/golang-announce/Kw31K8G7Fi0
https://security.gentoo.org/glsa/201812-09
Third Party Advisory
Mitigation