Lucene search

K
mageiaGentoo FoundationMGASA-2022-0444
HistoryNov 27, 2022 - 11:51 p.m.

Updated golang packages fix security vulnerability

2022-11-2723:51:49
Gentoo Foundation
advisories.mageia.org
22
golang
packages
update
security
vulnerability
cve-2022-41716
runtime
fatal error
unix
environment variables

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

0.001 Low

EPSS

Percentile

42.1%

Fixed unsanitized NUL in environment variables in syscalls, os/exec (go#56327) (bsc#1204941). (CVE-2022-41716) runtime: lock count" fatal error when cgo is enabled (go#56308)

OSVersionArchitecturePackageVersionFilename
Mageia8noarchgolang<ย 1.18.8-1golang-1.18.8-1.mga8

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

0.001 Low

EPSS

Percentile

42.1%