Lucene search

K
ubuntucveUbuntu.comUB:CVE-2023-39320
HistorySep 08, 2023 - 12:00 a.m.

CVE-2023-39320

2023-09-0800:00:00
ubuntu.com
ubuntu.com
11
go 1.21
module proxy
vcs software
package rebuilding
golang-1.21

9.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

0.001 Low

EPSS

Percentile

48.6%

The go.mod toolchain directive, introduced in Go 1.21, can be leveraged to
execute scripts and binaries relative to the root of the module when the
“go” command was executed within the module. This applies to modules
downloaded using the “go” command from the module proxy, as well as modules
downloaded directly using VCS software.

Notes

Author Note
mdeslaur Packages built using golang need to be rebuilt once the vulnerability has been fixed. This CVE entry does not list packages that need rebuilding outside of the main repository or the Ubuntu variants with PPA overlays.
sbeattie affects golang-1.21 only

9.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

0.001 Low

EPSS

Percentile

48.6%