CVE-2018-6574
Go before 1.8.7, Go 1.9.x before 1.9.4, and Go 1.10 pre-releases before Go 1.10rc2 allow "go get" remote command execution during source code build, by leveraging the gcc or clang plugin feature, because -fplugin= and -plugin= arguments were not blocked.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (7.63%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Go before 1.8.7, Go 1.9.x before 1.9.4, and Go 1.10 pre-releases before Go 1.10rc2 allow "go get" remote command execution during source code build, by leveraging the gcc or clang plugin feature, because -fplugin= and -plugin= arguments were not blocked.
- CVSS 3.0
- 7.8 HIGHCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 7.63% probability · 94th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-94
- Affected
- golang/go · debian/debian linux · redhat/enterprise linux server · redhat/enterprise linux server aus · redhat/enterprise linux server eus · redhat/enterprise linux server tus
- Source
- cve@mitre.org
References
- https://access.redhat.com/errata/RHSA-2018:0878Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:1304Third Party Advisory
- https://github.com/KINGSABRI/CVE-in-Ruby/tree/master/CVE-2018-6574Exploit, Third Party Advisory
- https://github.com/golang/go/issues/23672Issue Tracking, Third Party Advisory
- https://groups.google.com/forum/#%21topic/golang-nuts/Gbhh1NxAjMU
- https://groups.google.com/forum/#%21topic/golang-nuts/sprOaQ5m3Dk
- https://www.debian.org/security/2019/dsa-4380Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:0878Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:1304Third Party Advisory
- https://github.com/KINGSABRI/CVE-in-Ruby/tree/master/CVE-2018-6574Exploit, Third Party Advisory
- https://github.com/golang/go/issues/23672Issue Tracking, Third Party Advisory
- https://groups.google.com/forum/#%21topic/golang-nuts/Gbhh1NxAjMU
- https://groups.google.com/forum/#%21topic/golang-nuts/sprOaQ5m3Dk
- https://www.debian.org/security/2019/dsa-4380Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.