golang/go in 1.0.2 fixes all.bash on shared machines. dotest() in src/pkg/debug/gosym/pclntab_test.go creates a temporary file with predicable name and executes it as shell script.
Creating and using insecure temporary files can leave application and system data vulnerable to attack.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Go | Golang | 1.0.2 (including) | 1.0.2 (including) |
Golang | Ubuntu | trusty | * |
Golang | Ubuntu | upstream | * |
Golang-1.10 | Ubuntu | trusty | * |
Golang-1.16 | Ubuntu | trusty | * |
Golang-1.16 | Ubuntu | xenial | * |
Golang-1.6 | Ubuntu | trusty | * |