| Vulnerability Name: | CVE-2016-3958 (CCN-112329) | ||||||||||||
| Assigned: | 2016-04-05 | ||||||||||||
| Published: | 2016-04-05 | ||||||||||||
| Updated: | 2022-08-16 | ||||||||||||
| Summary: | Untrusted search path vulnerability in Go before 1.5.4 and 1.6.x before 1.6.1 on Windows allows local users to gain privileges via a Trojan horse DLL in the current working directory, related to use of the LoadLibrary function. | ||||||||||||
| CVSS v3 Severity: | 7.8 High (CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H) 6.8 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
7.3 High (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
| ||||||||||||
| CVSS v2 Severity: | 7.2 High (CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C)
| ||||||||||||
| Vulnerability Type: | CWE-264 | ||||||||||||
| Vulnerability Consequences: | Gain Privileges | ||||||||||||
| References: | Source: MITRE Type: CNA CVE-2016-3958 Source: CCN Type: oss-sec Mailing List, Tue, 05 Apr 2016 17:19:31 +0000 CVE request - Go - DLL loading, Big int Source: CCN Type: oss-sec Mailing List, Tue, 5 Apr 2016 14:31:03 -0400 (EDT) Re: CVE request - Go - DLL loading, Big int Source: MLIST Type: Mailing List, Third Party Advisory [oss-security] 20160405 CVE request - Go - DLL loading, Big int Source: MLIST Type: Mailing List, Third Party Advisory [oss-security] 20160405 Re: CVE request - Go - DLL loading, Big int Source: XF Type: UNKNOWN go-cve20163958-priv-esc(112329) Source: CONFIRM Type: Third Party Advisory https://github.com/golang/go/issues/14959 Source: CCN Type: Go Web site Patch 21428 Source: CONFIRM Type: Vendor Advisory https://go-review.googlesource.com/#/c/21428/ Source: MLIST Type: Mailing List, Third Party Advisory [golang-announce] 20160412 [security] Go 1.6.1 and 1.5.4 are released Source: CCN Type: WhiteSource Vulnerability Database CVE-2016-3958 | ||||||||||||
| Vulnerable Configuration: | Configuration 1: Configuration 2: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||
| Oval Definitions | |||||||||||||
| |||||||||||||
| BACK | |||||||||||||