CVE-2012-2666
published 2021-07-09CVE-2012-2666: golang/go in 1.0.2 fixes all.bash on shared machines. dotest() in src/pkg/debug/gosym/pclntab_test.go creates a temporary file with predicable name and…
PriorityP345critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
1.93%
77.5th percentile
golang/go in 1.0.2 fixes all.bash on shared machines. dotest() in src/pkg/debug/gosym/pclntab_test.go creates a temporary file with predicable name and executes it as shell script.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| go | golang | — | — |
| golang | go | — | — |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://bugzilla.suse.com/show_bug.cgi?id=765455https://codereview.appspot.com/5992078https://github.com/golang/go/commit/8ac275bb01588a8c0e6c0fe2de7fd11f08feccddhttps://security.netapp.com/advisory/ntap-20210902-0009/https://www.whitesourcesoftware.com/vulnerability-database/CVE-2012-2666https://bugzilla.suse.com/show_bug.cgi?id=765455https://codereview.appspot.com/5992078https://github.com/golang/go/commit/8ac275bb01588a8c0e6c0fe2de7fd11f08feccddhttps://security.netapp.com/advisory/ntap-20210902-0009/https://www.whitesourcesoftware.com/vulnerability-database/CVE-2012-2666
2021-07-09
Published