Sylvain Beucler pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
59ccb3a7 by Sylvain Beucler at 2023-04-14T23:40:03+02:00
CVE-2020-28367/golang: reference patch and regression fix
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -185663,6 +185663,8 @@ CVE-2020-28367 (Code injection in the go command with
cgo before Go 1.14.12 and
[stretch] - golang-1.7 <ignored> (validation of cgo flags first
introduced in golang-1.8 / CVE-2018-6574)
NOTE:
https://groups.google.com/g/golang-announce/c/NpBGTTmKzpM/m/fLguyiM2CAAJ
NOTE: https://github.com/golang/go/issues/42556
+ NOTE: Fixed by:
https://github.com/golang/go/commit/da7aa86917811a571e6634b45a457f918b8e6561
(go1.16beta1)
+ NOTE: Regression:
https://github.com/golang/go/commit/782cf560db4c919790fdb476d1bbe18e5ddf5ffd
(go1.16beta1)
CVE-2020-28366 (Code injection in the go command with cgo before Go 1.14.12
and Go 1.1 ...)
- golang-1.15 1.15.5-1
- golang-1.11 <removed>
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/59ccb3a7b06612f1a72f679f50943f3bf5eaca52
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/59ccb3a7b06612f1a72f679f50943f3bf5eaca52
You're receiving this email because of your account on salsa.debian.org.
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits