Ubuntu Security Notice USN-7061-1

Discussion in 'News Aggregator' started by Packet Storm, 11 Oct 2024.

  1. Packet Storm

    Packet Storm Guest

    Ubuntu Security Notice 7061-1 - Hunter Wittenborn discovered that Go incorrectly handled the sanitization of environment variables. An attacker could possibly use this issue to run arbitrary commands. Sohom Datta discovered that Go did not properly validate backticks as Javascript string delimiters, and did not escape them as expected. An attacker could possibly use this issue to inject arbitrary Javascript code into the Go template.

    Continue reading...
     

Share This Page

Loading...