CVE-2017-1000097
05.10.2017, 01:29
On Darwin, user's trust preferences for root certificates were not honored. If the user had a root certificate loaded in their Keychain that was explicitly not trusted, a Go program would still verify a connection using that root certificate.Enginsight
Vendor | Product | Version |
---|---|---|
golang | go | 𝑥 < 1.6.4 |
golang | go | 1.7 ≤ 𝑥 < 1.7.4 |
𝑥
= Vulnerable software versions

Ubuntu Releases
Common Weakness Enumeration
References