Golang Go CVE-2018-16873 Remote Code Execution Vulnerability
BID:106226
CVE-2018-16873 |Info
Golang Go CVE-2018-16873 Remote Code Execution Vulnerability
| Bugtraq ID: | 106226 |
| Class: | Unknown |
| CVE: |
CVE-2018-16873 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 13 2018 12:00AM |
| Updated: | Dec 13 2018 12:00AM |
| Credit: | Etienne Stalmans from the Heroku platform security team. |
| Vulnerable: |
Redhat Gluster Storage 3.0 Redhat Ceph Storage 3 Redhat Ceph Storage 2 golang Go 1.11.2 golang Go 1.11.1 golang Go 1.10.5 golang Go 1.10.4 golang Go 1.10.3 golang Go 1.10.2 golang Go 1.10.1 golang Go 1.11 golang Go 1.10 |
| Not Vulnerable: |
golang Go 1.11.3 golang Go 1.10.6 |
References
Golang Go CVE-2018-16873 Remote Code Execution Vulnerability
References:
References:
- [security] Go 1.11.3 and Go 1.10.6 pre-announcement (Google)
- Bug 1657563 (CVE-2018-16873) - CVE-2018-16873 golang: "go get" command vulnerabl (Red Hat Bugzilla)
- cmd/go: remote command execution during "go get -u" (Golang)
- CVE-2018-16873 (Red Hat Bugzilla)
- Go Homepage (golang)