Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2024-8876

Опубликовано: 05 нояб. 2024
Источник: oracle-oval
Платформа: Oracle Linux 8

Описание

ELSA-2024-8876: go-toolset:ol8 security update (MODERATE)

delve [1.22.1-1.0.1]

  • Disable DWARF compression which has issues (Alex Burmashev)

[1.22.1-1]

  • Rebase to 1.22.1
  • Resolves: RHEL-54307

golang [1.22.7-1]

  • Update to Go 1.22.7
  • Resolves: RHEL-58223
  • Resolves: RHEL-57961
  • Resolves: RHEL-57847
  • Resolves: RHEL-57860

[1.22.5-3]

  • Update fix that loads Openssl in FIPS mode if fips==1
  • Related: RHEL-52485

[1.22.5-2]

  • Include fix that loads Openssl only in FIPS mode to avoid panic
  • Resolves: RHEL-52485

[1.22.5-1]

  • Rebase to Go1.22.5 to fix CVE-2024-24791
  • Resolves: RHEL-46972

[1.22.4-1]

  • Addresses CVEs-2024-24789 and CVE-2024-24790
  • Resolves: RHEL-40157

[1.22.3-3]

  • Update openssl backend
  • Resolves: RHEL-36102

[1.22.3-2]

  • Restore HashSign / HashVerify API
  • Resolves: RHEL-35884

[1.22.3-1]

  • Update to Go 1.22.3
  • Resolves: RHEL-35884
  • Resolves: RHEL-35075
  • Resolves: RHEL-35632
  • Resolves: RHEL-35901

[1.22.2-1]

  • Rebase to 1.22.2
  • Re-enable CGO
  • Skip TestCrashDumpsAllThreads
  • Resolves: RHEL-33157

go-toolset [1.22.7-1]

  • Update to Go 1.22.7
  • Resolves: RHEL-58223
  • Resolves: RHEL-57961
  • Resolves: RHEL-57847
  • Resolves: RHEL-57860

[1.22.5-1]

  • Rebase to Go1.22.5 to fix CVE-2024-24791
  • Resolves: RHEL-46972

[1.22.4-1]

  • Addresses CVEs-2024-24789 and CVE-2024-24790
  • Resolves: RHEL-40157

[1.22.3-1]

  • Update to Go 1.22.3
  • Resolves: RHEL-35884
  • Resolves: RHEL-35075
  • Resolves: RHEL-35632
  • Resolves: RHEL-35901

[1.22.2-1]

  • Update to Go 1.22.2
  • Resolves: RHEL-33157

Обновленные пакеты

Oracle Linux 8

Oracle Linux aarch64

Module go-toolset:ol8 is enabled

delve

1.22.1-1.0.1.module+el8.10.0+90426+810ab996

go-toolset

1.22.7-1.module+el8.10.0+90426+810ab996

golang

1.22.7-1.module+el8.10.0+90426+810ab996

golang-bin

1.22.7-1.module+el8.10.0+90426+810ab996

golang-docs

1.22.7-1.module+el8.10.0+90426+810ab996

golang-misc

1.22.7-1.module+el8.10.0+90426+810ab996

golang-src

1.22.7-1.module+el8.10.0+90426+810ab996

golang-tests

1.22.7-1.module+el8.10.0+90426+810ab996

Oracle Linux x86_64

Module go-toolset:ol8 is enabled

delve

1.22.1-1.0.1.module+el8.10.0+90426+810ab996

go-toolset

1.22.7-1.module+el8.10.0+90426+810ab996

golang

1.22.7-1.module+el8.10.0+90426+810ab996

golang-bin

1.22.7-1.module+el8.10.0+90426+810ab996

golang-docs

1.22.7-1.module+el8.10.0+90426+810ab996

golang-misc

1.22.7-1.module+el8.10.0+90426+810ab996

golang-src

1.22.7-1.module+el8.10.0+90426+810ab996

golang-tests

1.22.7-1.module+el8.10.0+90426+810ab996

Связанные CVE

Связанные уязвимости

CVSS3: 9.8
ubuntu
около 1 года назад

The various Is methods (IsPrivate, IsLoopback, etc) did not work as expected for IPv4-mapped IPv6 addresses, returning false for addresses which would return true in their traditional IPv4 forms.

CVSS3: 6.7
redhat
около 1 года назад

The various Is methods (IsPrivate, IsLoopback, etc) did not work as expected for IPv4-mapped IPv6 addresses, returning false for addresses which would return true in their traditional IPv4 forms.

CVSS3: 9.8
nvd
около 1 года назад

The various Is methods (IsPrivate, IsLoopback, etc) did not work as expected for IPv4-mapped IPv6 addresses, returning false for addresses which would return true in their traditional IPv4 forms.

CVSS3: 9.8
debian
около 1 года назад

The various Is methods (IsPrivate, IsLoopback, etc) did not work as ex ...

suse-cvrf
4 месяца назад

Security update for google-osconfig-agent