Vulnerability Name: | CVE-2019-9634 (CCN-158172) | ||||||||||||||||||||||||||||||||
Assigned: | 2019-03-06 | ||||||||||||||||||||||||||||||||
Published: | 2019-03-06 | ||||||||||||||||||||||||||||||||
Updated: | 2022-08-16 | ||||||||||||||||||||||||||||||||
Summary: | Go through 1.12 on Windows misuses certain LoadLibrary functionality, leading to DLL injection. | ||||||||||||||||||||||||||||||||
CVSS v3 Severity: | 7.8 High (CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H) 6.8 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
6.8 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
| ||||||||||||||||||||||||||||||||
CVSS v2 Severity: | 6.8 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P)
| ||||||||||||||||||||||||||||||||
Vulnerability Type: | CWE-427 | ||||||||||||||||||||||||||||||||
Vulnerability Consequences: | Gain Access | ||||||||||||||||||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2019-9634 Source: MLIST Type: Mailing List, Third Party Advisory [oss-security] 20190409 DLL injection in Go < 1.12.2 [CVE-2019-9634] Source: BID Type: Third Party Advisory, VDB Entry 107450 Source: XF Type: UNKNOWN go-cve20199634-code-exec(158172) Source: CCN Type: go GIT Repository runtime: dll injection vulnerabilities on Windows (CVE-2019-9634) #30642 Source: MISC Type: Exploit, Issue Tracking, Patch, Third Party Advisory https://github.com/golang/go/issues/30642 Source: CCN Type: IBM Security Bulletin 960882 (API Connect) API Connect V2018 is impacted by vulnerabilities in golang (CVE-2019-9634) Source: CCN Type: IBM Security Bulletin 1143484 (Watson Studio Local) Multiple Vulnerabilities in Go affects IBM Watson Studio Local | ||||||||||||||||||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||||||||||||||||||||||||||
Oval Definitions | |||||||||||||||||||||||||||||||||
| |||||||||||||||||||||||||||||||||
BACK |