Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

CVEs in stdlib in current Go version 1.20 #601

Closed
chkp-erezca opened this issue Oct 31, 2024 · 1 comment · Fixed by #602
Closed

CVEs in stdlib in current Go version 1.20 #601

chkp-erezca opened this issue Oct 31, 2024 · 1 comment · Fixed by #602

Comments

@chkp-erezca
Copy link

chkp-erezca commented Oct 31, 2024

There are many CVEs (~180+) reported for stdlib which is used in sample32.macho and sample64.macho test files you have.
These CVEs start from Go 1.13 and you are using Go 1.20. Upgrading to 1.22.7 or above should solve all these CVEs. Is it possible to upgrade the Go version or alternatively change the relevant test files to use some other library with no CVEs?
Attaching screenshots with part of the CVE list.
image
image

@AndrewYEEE
Copy link

@gabriel-vasile hello. hope fix this problem, thank you><

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging a pull request may close this issue.

2 participants