NordSecurity / nordvpn-linux

NordVPN Linux client
GNU General Public License v3.0
307 stars 44 forks source link

Critical vulnerability in golang version used to compile released NordVPN binaries #247

Closed tmknight closed 9 months ago

tmknight commented 9 months ago

Please consider using the latest patch of 1.20 (1.20.13 as of this submission) to compile the NordVPN binaries:

stdlib:

Location:

https://nvd.nist.gov/vuln/detail/CVE-2023-24538 https://nvd.nist.gov/vuln/detail/CVE-2023-24540

piotrjurkiewicz commented 9 months ago

Fixed by #250. Thank you for the report.