blob: 0e5732113c21e7b05119e0d0d185a89d22897e58 [file] [log] [blame]
modules:
- module: std
versions:
- fixed: 1.11.10
- introduced: 1.12.0
fixed: 1.12.2
packages:
- package: runtime
goos:
- windows
symbols:
- loadOptionalSyscalls
- osinit
- syscall_loadsystemlibrary
- package: syscall
goos:
- windows
symbols:
- LoadDLL
description: |
Go on Windows misused certain LoadLibrary functionality, leading to DLL
injection.
published: 2022-05-25T18:01:46Z
cves:
- CVE-2019-9634
credit: Samuel Cochran, Jason Donenfeld
references:
- fix: https://go.dev/cl/165798
- fix: https://go.googlesource.com/go/+/9b6e9f0c8c66355c0f0575d808b32f52c8c6d21c
- report: https://go.dev/issue/28978
- web: https://groups.google.com/g/golang-announce/c/z9eTD34GEIs/m/Z_XmhTrVAwAJ