CERT-In finds multiple bugs in 'Golang Go' that affect IBM's data management software


New Delhi, June 22 (IANS): The Indian Computer Emergency Response Team (CERT-In), which comes under the Ministry of Electronics & Information Technology, has warned users of multiple vulnerabilities in the 'Golang Go' programming language affecting IBM Storage Copy Data Management software.

As per the CERT-In advisory, the multiple vulnerabilities -- 'arbitrary code execution vulnerability' and 'denial of service vulnerability' -- could allow an attacker to execute arbitrary code or cause a denial of service condition on the targeted system.

The arbitrary code execution vulnerability exists in IBM software due to a flaw in Golang Go during the build on Darwin.

"An attacker could exploit this vulnerability by building a specially crafted Go module. Successful exploitation of this vulnerability could allow an attacker to execute arbitrary code on the targeted system," the cyber agency said.

On the other hand, the denial of service vulnerability exists in IBM Storage Copy Data Management due to a flaw in Golang Go which causes high CPU usage in the 'extractExtendedRCode' function in the net module.

"A remote attacker could exploit this vulnerability by sending a specially crafted DNS message in response to a query," the advisory mentioned.

Successful exploitation of this vulnerability could allow an attacker to cause a denial of service condition on the targeted system.

CERT-In has suggested users apply appropriate fix/patches as recommended by the company.

 

  

Top Stories


Leave a Comment

Title: CERT-In finds multiple bugs in 'Golang Go' that affect IBM's data management software



You have 2000 characters left.

Disclaimer:

Please write your correct name and email address. Kindly do not post any personal, abusive, defamatory, infringing, obscene, indecent, discriminatory or unlawful or similar comments. Daijiworld.com will not be responsible for any defamatory message posted under this article.

Please note that sending false messages to insult, defame, intimidate, mislead or deceive people or to intentionally cause public disorder is punishable under law. It is obligatory on Daijiworld to provide the IP address and other details of senders of such comments, to the authority concerned upon request.

Hence, sending offensive comments using daijiworld will be purely at your own risk, and in no way will Daijiworld.com be held responsible.