CVE-2012-2666: Golang Go
Critical severity, CVSS 9.8. EPSS: 1.9% chance of exploitation in the next 30 days.
golang/go in 1.0.2 fixes all.bash on shared machines. dotest() in src/pkg/debug/gosym/pclntab_test.go creates a temporary file with predicable name and executes it as shell script.
Affected products
- Golang Go: version 1.0.2 only
Published 2021-07-09. Last modified 2026-06-16.