Описание
Security update for go1.11
This update for go1.11 to version 1.11.5 fixes the following issues:
Security issue fixed:
- CVE-2019-6486: Fixed a CPU Denial-of-Service vulnerability affecting crypto/ellpitic related to P-521 and P-384 (bsc#1123013 go#29903).
Other bug fixes and changes made:
- Fix erroneous trailing backslash in %post script.
- Use better forms of -exec ; in some places.
This update was imported from the SUSE:SLE-15:Update update project.
Список пакетов
openSUSE Leap 15.0
go1.11-1.11.5-lp150.6.4
go1.11-doc-1.11.5-lp150.6.4
go1.11-race-1.11.5-lp150.6.4
Ссылки
- E-Mail link for openSUSE-SU-2019:1164-1
- SUSE Security Ratings
- SUSE Bug 1123013
- SUSE CVE CVE-2019-6486 page
Описание
Go before 1.10.8 and 1.11.x before 1.11.5 mishandles P-521 and P-384 elliptic curves, which allows attackers to cause a denial of service (CPU consumption) or possibly conduct ECDH private key recovery attacks.
Затронутые продукты
openSUSE Leap 15.0:go1.11-1.11.5-lp150.6.4
openSUSE Leap 15.0:go1.11-doc-1.11.5-lp150.6.4
openSUSE Leap 15.0:go1.11-race-1.11.5-lp150.6.4
Ссылки
- CVE-2019-6486
- SUSE Bug 1123013