CVE-2012-2666

golang/go in 1.0.2 fixes all.bash on shared machines. dotest() in src/pkg/debug/gosym/pclntab_test.go creates a temporary file with predicable name and executes it as shell script.
Configurations

Configuration 1 (hide)

cpe:2.3:a:golang:go:1.0.2:*:*:*:*:*:*:*

History

21 Nov 2024, 01:39

Type Values Removed Values Added
References () https://bugzilla.suse.com/show_bug.cgi?id=765455 - Issue Tracking, Patch, Third Party Advisory () https://bugzilla.suse.com/show_bug.cgi?id=765455 - Issue Tracking, Patch, Third Party Advisory
References () https://codereview.appspot.com/5992078 - Exploit, Third Party Advisory () https://codereview.appspot.com/5992078 - Exploit, Third Party Advisory
References () https://github.com/golang/go/commit/8ac275bb01588a8c0e6c0fe2de7fd11f08feccdd - Patch, Third Party Advisory () https://github.com/golang/go/commit/8ac275bb01588a8c0e6c0fe2de7fd11f08feccdd - Patch, Third Party Advisory
References () https://security.netapp.com/advisory/ntap-20210902-0009/ - Third Party Advisory () https://security.netapp.com/advisory/ntap-20210902-0009/ - Third Party Advisory
References () https://www.whitesourcesoftware.com/vulnerability-database/CVE-2012-2666 - Third Party Advisory () https://www.whitesourcesoftware.com/vulnerability-database/CVE-2012-2666 - Third Party Advisory

Information

Published : 2021-07-09 11:15

Updated : 2024-11-21 01:39


NVD link : CVE-2012-2666

Mitre link : CVE-2012-2666

CVE.ORG link : CVE-2012-2666


JSON object : View

Products Affected

golang

  • go
CWE
CWE-377

Insecure Temporary File