Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2024-7502

Опубликовано: 02 окт. 2024
Источник: oracle-oval
Платформа: Oracle Linux 8

Описание

ELSA-2024-7502: go-toolset:ol8 security update (MODERATE)

delve golang [1.21.13-3]

  • Add evp-digest-sign-final.patch
  • Resolves: RHEL-61109

go-toolset

Обновленные пакеты

Oracle Linux 8

Oracle Linux aarch64

Module go-toolset:ol8 is enabled

delve

1.21.2-4.0.1.module+el8.10.0+90414+fc21c2ff

go-toolset

1.21.13-1.module+el8.10.0+90414+fc21c2ff

golang

1.21.13-3.module+el8.10.0+90414+fc21c2ff

golang-bin

1.21.13-3.module+el8.10.0+90414+fc21c2ff

golang-docs

1.21.13-3.module+el8.10.0+90414+fc21c2ff

golang-misc

1.21.13-3.module+el8.10.0+90414+fc21c2ff

golang-src

1.21.13-3.module+el8.10.0+90414+fc21c2ff

golang-tests

1.21.13-3.module+el8.10.0+90414+fc21c2ff

Oracle Linux x86_64

Module go-toolset:ol8 is enabled

delve

1.21.2-4.0.1.module+el8.10.0+90414+fc21c2ff

go-toolset

1.21.13-1.module+el8.10.0+90414+fc21c2ff

golang

1.21.13-3.module+el8.10.0+90414+fc21c2ff

golang-bin

1.21.13-3.module+el8.10.0+90414+fc21c2ff

golang-docs

1.21.13-3.module+el8.10.0+90414+fc21c2ff

golang-misc

1.21.13-3.module+el8.10.0+90414+fc21c2ff

golang-src

1.21.13-3.module+el8.10.0+90414+fc21c2ff

golang-tests

1.21.13-3.module+el8.10.0+90414+fc21c2ff

Связанные CVE

Связанные уязвимости

CVSS3: 6.5
redhat
9 месяцев назад

A vulnerability was found in Golang FIPS OpenSSL. This flaw allows a malicious user to randomly cause an uninitialized buffer length variable with a zeroed buffer to be returned in FIPS mode. It may also be possible to force a false positive match between non-equal hashes when comparing a trusted computed hmac sum to an untrusted input sum if an attacker can send a zeroed buffer in place of a pre-computed sum.  It is also possible to force a derived key to be all zeros instead of an unpredictable value.  This may have follow-on implications for the Go TLS stack.

CVSS3: 6.5
nvd
9 месяцев назад

A vulnerability was found in Golang FIPS OpenSSL. This flaw allows a malicious user to randomly cause an uninitialized buffer length variable with a zeroed buffer to be returned in FIPS mode. It may also be possible to force a false positive match between non-equal hashes when comparing a trusted computed hmac sum to an untrusted input sum if an attacker can send a zeroed buffer in place of a pre-computed sum.  It is also possible to force a derived key to be all zeros instead of an unpredictable value.  This may have follow-on implications for the Go TLS stack.

CVSS3: 6.5
msrc
6 месяцев назад

Описание отсутствует

rocky
7 месяцев назад

Moderate: grafana-pcp security update

rocky
8 месяцев назад

Moderate: golang security update