VDB
BDU%3A2025-08600
BDU%3A2025-08600
PUBLISHED
CVSS 4.599999904632568 MEDIUM
Уязвимость языка программирования Golang, связанная с неверным определением символических ссылок перед доступом к файлу, позволяющая нарушителю повысить привилегии в системе
Risk Scores
CVSS 2.0
4.599999904632568
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| ООО «Ред Софт», Novell Inc., The Go Project | РЕД ОС (запись в едином реестре российских программ №3751), SUSE Linux Enterprise Server for SAP Applications, SUSE Enterprise Storage, Suse Linux Enterprise Server, SUSE Linux Enterprise High Performance Computing, Suse Linux Enterprise Desktop, OpenSUSE Leap, SUSE Linux Enterprise Module for Development Tools, Go |
Timeline
- Jul 17, 2025 CVE Published
References
- https://go.dev/issue/73702_x0001_ url
- https://go.dev/cl/672396_x0001_ advisory
- https://groups.google.com/g/golang-announce/c/ufZ8WpEsA3A_x0001_ advisory
- https://www.suse.com/security/cve/CVE-2025-0913.html url
- https://pkg.go.dev/vuln/GO-2025-3750 url
- https://redos.red-soft.ru/support/secure/uyazvimosti/mnozhestvennye-uyazvimosti-golang-cve-2025-4673-cve-2025-0913-cve-2025-22874/?sphrase_id=1076444 url