Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2021-36221

Опубликовано: 08 авг. 2021
Источник: debian

Описание

Go before 1.15.15 and 1.16.x before 1.16.7 has a race condition that can lead to a net/http/httputil ReverseProxy panic upon an ErrAbortHandler abort.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
golang-1.16fixed1.16.7-1package
golang-1.15fixed1.15.15-1package
golang-1.15fixed1.15.15-1~deb11u1bullseyepackage
golang-1.11removedpackage
golang-1.8removedpackage
golang-1.7removedpackage

Примечания

  • https://github.com/golang/go/issues/46866

  • https://github.com/golang/go/commit/b7a85e0003cedb1b48a1fd3ae5b746ec6330102e (master)

  • https://github.com/golang/go/commit/accf363d5da864521c90b152fb734f3f15e00521 (release-branch.go1.16)

  • https://github.com/golang/go/commit/ba93baa74a52d57ae79313313ea990cc791ef50e (release-branch.go1.15)

Связанные уязвимости

CVSS3: 5.9
ubuntu
почти 4 года назад

Go before 1.15.15 and 1.16.x before 1.16.7 has a race condition that can lead to a net/http/httputil ReverseProxy panic upon an ErrAbortHandler abort.

CVSS3: 5.9
redhat
почти 4 года назад

Go before 1.15.15 and 1.16.x before 1.16.7 has a race condition that can lead to a net/http/httputil ReverseProxy panic upon an ErrAbortHandler abort.

CVSS3: 5.9
nvd
почти 4 года назад

Go before 1.15.15 and 1.16.x before 1.16.7 has a race condition that can lead to a net/http/httputil ReverseProxy panic upon an ErrAbortHandler abort.

CVSS3: 5.9
msrc
почти 4 года назад

Описание отсутствует

suse-cvrf
почти 4 года назад

Security update for go1.16