CVE-2018-7187
golang-1.7 - security update
EPSS 63.2%
描述
The "go get" command is vulnerable to remote code execution. When the -insecure command-line option is used, "go get" does not validate the import path (get/vcs.go only checks for "://" anywhere in the string), which allows remote attackers to execute arbitrary OS commands via a crafted web site.
如何修補 CVE-2018-7187
要修補 CVE-2018-7187,請將受影響套件升級到下列已修補版本。
- Debian/golang—升級至 2:1.0.2-1.1+deb7u3 或更新版本
- Debian/golang-1.7—升級至 1.7.4-2+deb9u1 或更新版本
- Go/toolchain—升級至 1.9.5 或更新版本
CVE-2018-7187 正在被利用嗎?
可能 — EPSS 為 63.2%,屬於高被利用機率區間,建議優先修補。
受影響套件(3)
- from 0, < 2:1.0.2-1.1+deb7u3
- from 0, < 1.7.4-2+deb9u1
- from 0, < 1.9.5, >= 1.10.0-0, < 1.10.1