CVE-2019-9634
Published: 8 March 2019
Go through 1.12 on Windows misuses certain LoadLibrary functionality, leading to DLL injection.
Notes
Author | Note |
---|---|
mdeslaur | Packages built using golang need to be rebuilt once the vulnerability has been fixed. This CVE entry does not list packages that need rebuilding outside of the main repository or the Ubuntu variants with PPA overlays. |
sbeattie | affects Go only on Windows |
Priority
Status
Package | Release | Status |
---|---|---|
golang Launchpad, Ubuntu, Debian |
bionic |
Does not exist
|
cosmic |
Does not exist
|
|
disco |
Does not exist
|
|
precise |
Does not exist
|
|
trusty |
Does not exist
(trusty was not-affected)
|
|
upstream |
Needs triage
|
|
xenial |
Does not exist
|
|
golang-1.10 Launchpad, Ubuntu, Debian |
bionic |
Not vulnerable
(windows only)
|
cosmic |
Not vulnerable
(windows only)
|
|
disco |
Not vulnerable
(windows only)
|
|
precise |
Does not exist
|
|
trusty |
Not vulnerable
|
|
upstream |
Not vulnerable
(debian: Only affects Go on Windows)
|
|
xenial |
Not vulnerable
(windows only)
|
|
golang-1.11 Launchpad, Ubuntu, Debian |
bionic |
Does not exist
|
cosmic |
Does not exist
|
|
disco |
Not vulnerable
(windows only)
|
|
precise |
Does not exist
|
|
trusty |
Does not exist
|
|
upstream |
Not vulnerable
(debian: Only affects Go on Windows)
|
|
xenial |
Does not exist
|
|
golang-1.12 Launchpad, Ubuntu, Debian |
bionic |
Does not exist
|
cosmic |
Does not exist
|
|
disco |
Not vulnerable
(windows only)
|
|
precise |
Does not exist
|
|
trusty |
Does not exist
|
|
upstream |
Not vulnerable
(debian: Only affects Go on Windows)
|
|
xenial |
Does not exist
|
|
golang-1.6 Launchpad, Ubuntu, Debian |
bionic |
Does not exist
|
cosmic |
Does not exist
|
|
disco |
Does not exist
|
|
precise |
Does not exist
|
|
trusty |
Does not exist
(trusty was not-affected)
|
|
upstream |
Not vulnerable
(windows only)
|
|
xenial |
Not vulnerable
(windows only)
|
|
golang-1.7 Launchpad, Ubuntu, Debian |
bionic |
Does not exist
|
cosmic |
Not vulnerable
(windows only)
|
|
disco |
Does not exist
|
|
precise |
Does not exist
|
|
trusty |
Does not exist
|
|
upstream |
Not vulnerable
(windows only)
|
|
xenial |
Does not exist
|
|
golang-1.8 Launchpad, Ubuntu, Debian |
bionic |
Not vulnerable
(windows only)
|
cosmic |
Not vulnerable
(windows only)
|
|
disco |
Does not exist
|
|
precise |
Does not exist
|
|
trusty |
Does not exist
|
|
upstream |
Not vulnerable
(windows only)
|
|
xenial |
Does not exist
|
|
golang-1.9 Launchpad, Ubuntu, Debian |
bionic |
Not vulnerable
(windows only)
|
cosmic |
Not vulnerable
(windows only)
|
|
disco |
Does not exist
|
|
precise |
Does not exist
|
|
trusty |
Does not exist
|
|
upstream |
Not vulnerable
(windows only)
|
|
xenial |
Does not exist
|
Severity score breakdown
Parameter | Value |
---|---|
Base score | 7.8 |
Attack vector | Local |
Attack complexity | Low |
Privileges required | None |
User interaction | Required |
Scope | Unchanged |
Confidentiality | High |
Integrity impact | High |
Availability impact | High |
Vector | CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |