diff options
author | Roland Shoemaker <roland@golang.org> | 2021-01-15 12:14:06 -0800 |
---|---|---|
committer | Roland Shoemaker <bracewell@google.com> | 2021-01-16 00:29:16 +0000 |
commit | 07e3195293ec510171d7d43ec8ac2bcb9cf00df4 (patch) | |
tree | 3a36f93eab5c8dad04fb6f0963199b669fe5986c /src/cmd/cover/func.go | |
parent | b21052258ef27a7b267df21411dd4e8ddbdee5fe (diff) | |
download | go-07e3195293ec510171d7d43ec8ac2bcb9cf00df4.tar.gz go-07e3195293ec510171d7d43ec8ac2bcb9cf00df4.zip |
[release-branch.go1.15-security] all: introduce and use internal/execabs
Introduces a wrapper around os/exec, internal/execabs, for use in
all commands. This wrapper prevents exec.LookPath and exec.Command from
running executables in the current directory.
All imports of os/exec in non-test files in cmd/ are replaced with
imports of internal/execabs.
This issue was reported by RyotaK.
Fixes CVE-2021-3115
Change-Id: I0423451a6e27ec1e1d6f3fe929ab1ef69145c08f
Reviewed-on: https://team-review.git.corp.google.com/c/golang/go-private/+/955304
Reviewed-by: Russ Cox <rsc@google.com>
Reviewed-by: Katie Hockman <katiehockman@google.com>
(cherry picked from commit 44f09a6990ccf4db601cbf8208c89ac4e888f884)
Reviewed-on: https://team-review.git.corp.google.com/c/golang/go-private/+/955308
Diffstat (limited to 'src/cmd/cover/func.go')
-rw-r--r-- | src/cmd/cover/func.go | 2 |
1 files changed, 1 insertions, 1 deletions
diff --git a/src/cmd/cover/func.go b/src/cmd/cover/func.go index 988c4caebf..ce7c771ac9 100644 --- a/src/cmd/cover/func.go +++ b/src/cmd/cover/func.go @@ -15,9 +15,9 @@ import ( "go/ast" "go/parser" "go/token" + exec "internal/execabs" "io" "os" - "os/exec" "path" "path/filepath" "runtime" |