Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

rocky логотип

RLSA-2022:5799

Опубликовано: 01 авг. 2022
Источник: rocky
Оценка: Important

Описание

Important: go-toolset and golang security and bug fix update

Go Toolset provides the Go programming language tools and libraries. Go is alternatively known as golang.

The golang packages provide the Go programming language compiler.

Security Fix(es):

  • golang: compress/gzip: stack exhaustion in Reader.Read (CVE-2022-30631)

  • golang: net/http: improper sanitization of Transfer-Encoding header (CVE-2022-1705)

  • golang: go/parser: stack exhaustion in all Parse* functions (CVE-2022-1962)

  • golang: encoding/xml: stack exhaustion in Decoder.Skip (CVE-2022-28131)

  • golang: io/fs: stack exhaustion in Glob (CVE-2022-30630)

  • golang: path/filepath: stack exhaustion in Glob (CVE-2022-30632)

  • golang: encoding/xml: stack exhaustion in Unmarshal (CVE-2022-30633)

  • golang: encoding/gob: stack exhaustion in Decoder.Decode (CVE-2022-30635)

  • golang: net/http/httputil: NewSingleHostReverseProxy - omit X-Forwarded-For not working (CVE-2022-32148)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Bug Fix(es):

  • Clean up dist-git patches (BZ#2109174)

  • Update Go to version 1.17.12 (BZ#2109183)

Затронутые продукты

  • Rocky Linux 9

НаименованиеАрхитектураРелизRPM
golangx86_641.el9_0golang-1.17.12-1.el9_0.x86_64.rpm
golang-binx86_641.el9_0golang-bin-1.17.12-1.el9_0.x86_64.rpm
golang-docsnoarch1.el9_0golang-docs-1.17.12-1.el9_0.noarch.rpm
golang-docsnoarch1.el9_0golang-docs-1.17.12-1.el9_0.noarch.rpm
golang-docsnoarch1.el9_0golang-docs-1.17.12-1.el9_0.noarch.rpm
golang-docsnoarch1.el9_0golang-docs-1.17.12-1.el9_0.noarch.rpm
golang-miscnoarch1.el9_0golang-misc-1.17.12-1.el9_0.noarch.rpm
golang-miscnoarch1.el9_0golang-misc-1.17.12-1.el9_0.noarch.rpm
golang-miscnoarch1.el9_0golang-misc-1.17.12-1.el9_0.noarch.rpm
golang-miscnoarch1.el9_0golang-misc-1.17.12-1.el9_0.noarch.rpm

Показывать по

Связанные уязвимости

suse-cvrf
больше 2 лет назад

Security update for go1.18-openssl

rocky
больше 3 лет назад

Important: go-toolset:rhel8 security and bug fix update

oracle-oval
больше 3 лет назад

ELSA-2022-5799: go-toolset and golang security and bug fix update (IMPORTANT)

oracle-oval
больше 3 лет назад

ELSA-2022-5775: go-toolset:ol8 security and bug fix update (IMPORTANT)

suse-cvrf
больше 3 лет назад

Security update for go1.18