Huawei EulerOS: Security Advisory for golang (EulerOS-SA-2020-1008)

Published: 2020-01-23 13:15:21
CVE Author: NIST National Vulnerability Database (NVD)

CVSS Base Vector:
AV:N/AC:L/Au:N/C:N/I:N/A:C

Summary:
The remote host is missing an update for the Huawei EulerOS 'golang' Linux Distribution Package(s) announced via the EulerOS-SA-2020-1008 advisory.

Detection Method:
Checks if a vulnerable Linux Distribution Package version is present on the target host.

Technical Details:
In Go before 1.10.6 and 1.11.x before 1.11.3, the 'go get' command is vulnerable to directory traversal when executed with the import path of a malicious Go Linux Distribution Package which contains curly braces (both '{' and '}' characters). Specifically, it is only vulnerable in GOPATH mode, but not in module mode (the distinction is documented at the linked references). The attacker can cause an arbitrary filesystem write, which can lead to code execution.(CVE-2018-16874) The crypto/x509 Linux Distribution Package of Go before 1.10.6 and 1.11.x before 1.11.3 does not limit the amount of work performed for each chain verification, which might allow attackers to craft pathological inputs leading to a CPU denial of service. Go TLS servers accepting client certificates and TLS clients are affected.(CVE-2018-16875)

Affected Versions:
'golang' Linux Distribution Package(s) on Huawei EulerOS V2.0SP8.

Recommendations:
Please install the updated Linux Distribution Package(s).

Solution Type:
Vendor Patch

Detection Type:
Linux Distribution Package

NIST (National Institute of Standards and Technology) NVD (National Vulnerability Database)

https://nvd.nist.gov/vuln/detail/CVE-2018-16874
https://nvd.nist.gov/vuln/detail/CVE-2018-16875

References:

https://developer.huaweicloud.com/ict/en/site-euleros/euleros/security-advisories/EulerOS-SA-2020-1008
https://golang.org/cmd/go/#hdr-Module_aware_go_get

Search
Severity
High
CVSS Score
7.8

You never have to pay for a vulnerability scanning and management software again.

Tired of paying a subscription 'per asset' or 'per IP'? Well you can officially cancel your current subscription. Mageni provides a free, open source and enterprise-ready vulnerability scanning and management platform which helps you to find, prioritize, remediate and manage your vulnerabilities. It is free and always will be.