HomeDefault status
unaffected
Any version before 1.25.10
affected
1.26.0-0 (semver) before 1.26.3
affected
Description
The "go bug" command writes to two files with predictable names in the system temporary directory (for example, "/tmp"). An attacker with access to the temporary directory can create a symlink in one of these names, causing "go bug" to overwrite the target of the symlink.
Problem types
CWE-377: Insecure Temporary File
Product status
Any version before 1.25.10
1.26.0-0 (semver) before 1.26.3
Credits
Harshit Gupta (Mr HAX)
References
groups.google.com/g/golang-announce/c/qcCIEXso47M