ZeroHour

CVE-2020-28367

CVSS 3.1
7.5 high
EPSS
2%p84
Published
()
Modified
Description

Code injection in the go command with cgo before Go 1.14.12 and Go 1.15.5 allows arbitrary code execution at build time via malicious gcc flags specified via a #cgo directive.

Vendors
golang
Products
go
Weakness
CWE-94
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.