{"id":"MGASA-2018-0089","summary":"Updated golang packages fix security vulnerabilities","details":"An arbitrary command execution flaw was found in the way Go's \"go get\"\ncommand handled the checkout of source code repositories. A remote\nattacker capable of hosting malicious repositories could potentially use\nthis flaw to cause arbitrary command execution on the client side\n(CVE-2017-15041).\n\nIt was found that smtp.PlainAuth authentication scheme in Go did not\nverify the TLS requirement properly. A remote man-in-the-middle attacker\ncould potentially use this flaw to sniff SMTP credentials sent by a Go\napplication (CVE-2017-15042).\n","modified":"2026-04-16T06:24:11.553779908Z","published":"2018-01-21T21:31:56Z","upstream":["CVE-2017-15041","CVE-2017-15042"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2018-0089.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=21857"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/AHH5B4WHCPTVEM6APRVXRWLFOR325CCD/"}],"affected":[{"package":{"name":"golang","ecosystem":"Mageia:6","purl":"pkg:rpm/mageia/golang?arch=source&distro=mageia-6"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.9.1-1.mga6"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2018-0089.json"}}],"schema_version":"1.7.5","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}