Wheezy update of golang?

2018-02-16 Thread Antoine Beaupre
Dear maintainer(s), The Debian LTS team would like to fix the security issues which are currently open in the Wheezy version of golang: https://security-tracker.debian.org/tracker/CVE-2018-6574 Would you like to take care of this yourself? If yes, please follow the workflow we have defined

Re: Wheezy update of golang?

2017-10-27 Thread Antoine Beaupré
On 2017-10-24 15:44:18, Antoine Beaupré wrote: > Hi, > > After further analysis for the issues affecting golang in Wheezy, I have > concluded that it is not necessary to perform updates. > > CVE-2017-15041 concerns only the "go get" command, and only malicious > Subversion repositories which can

Re: Wheezy update of golang?

2017-10-24 Thread Antoine Beaupré
Hi, After further analysis for the issues affecting golang in Wheezy, I have concluded that it is not necessary to perform updates. CVE-2017-15041 concerns only the "go get" command, and only malicious Subversion repositories which can *then* chain into malicious git repositories. But then "go

Wheezy update of golang?

2017-10-14 Thread Ola Lundqvist
Dear maintainers, The Debian LTS team would like to fix the security issues which are currently open in the Wheezy version of golang: https://security-tracker.debian.org/tracker/CVE-2017-15041 https://security-tracker.debian.org/tracker/CVE-2017-15042 Would you like to take care of this