—
GO-2021-0068
Arbitrary code injection via the go command with cgo on Windows in cmd/go
Quick fix
GO-2021-0068 — toolchain: upgrade to the fixed version with the command below.
go get toolchain@v1.14.14Details
The go command may execute arbitrary code at build time when using cgo on Windows. This can be triggered by running go get on a malicious module, or any other time the code is built.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://go.dev/cl/284783[FIX]
- https://go.googlesource.com/go/+/953d1feca9b21af075ad5fc8a3dad096d3ccc3a0[FIX]
- https://go.dev/issue/43783[REPORT]
- https://groups.google.com/g/golang-announce/c/mperVMGa98w/m/yo5W5wnvAAAJ[WEB]
- https://go.dev/cl/284780[FIX]
- https://go.googlesource.com/go/+/46e2e2e9d99925bbf724b12693c6d3e27a95d6a0[FIX]