GLSA-201812-09 : Go: Multiple vulnerabilities
High Nessus Plugin ID 119852
SynopsisThe remote Gentoo host is missing one or more security-related patches.
DescriptionThe remote host is affected by the vulnerability described in GLSA-201812-09 (Go: Multiple vulnerabilities)
Multiple vulnerabilities have been discovered in Go. Please review the CVE identifiers referenced below for details.
A remote attacker could cause arbitrary code execution by passing specially crafted Go packages the ‘go get -u’ command.
The remote attacker could also craft pathological inputs causing a CPU based Denial of Service condition via the crypto/x509 package.
There is no known workaround at this time.
SolutionAll Go users should upgrade to the latest version:
# emerge --sync # emerge --ask --oneshot --verbose '>=dev-lang/go-1.10.7'