Vulnerabilities > CVE-2012-2666 - Insecure Temporary File vulnerability in Golang GO 1.0.2

047910
CVSS 9.8 - CRITICAL
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
HIGH
network
low complexity
golang
CWE-377
critical

Summary

golang/go in 1.0.2 fixes all.bash on shared machines. dotest() in src/pkg/debug/gosym/pclntab_test.go creates a temporary file with predicable name and executes it as shell script.

Vulnerable Configurations

Part Description Count
Application
Golang
1

Common Weakness Enumeration (CWE)