QID 352291
Date Published: 2021-05-19
QID 352291: Amazon Linux Security Update for golang: AL2012-2021-332
Package updates are available for Amazon Linux that fix the following vulnerabilities:
CVE-2020-28367:
1897646:
CVE-2020-28367 golang: improper validation of cgo flags can lead to code execution at build time
Go before 1.14.12 and 1.15.x before 1.15.5 allows Argument Injection.
CVE-2020-28366:
1897643:
CVE-2020-28366 golang: malicious symbol names can lead to code execution at build time
Go before 1.14.12 and 1.15.x before 1.15.5 allows Code Injection.
CVE-2020-28362:
1897635:
CVE-2020-28362 golang: math/big: panic during recursive division of very large numbers
Go before 1.14.12 and 1.15.x before 1.15.4 allows Denial of Service.
Note: The preceding description block is extracted directly from the security advisory. Using automation, we have attempted to clean and format it as much as possible without introducing additional issues.
Allows unauthorized disclosure of information; allows unauthorized modification; allows disruption of service.
CVEs related to QID 352291
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| AL2012-2021-332 | Amazon Linux Bare Metal |
|