Описание
Security update for go1.17
This update for go1.17 fixes the following issues:
Update to go1.17.2
- CVE-2021-38297: misc/wasm, cmd/link: do not let command line args overwrite global data (bsc#1191468)
Список пакетов
openSUSE Leap 15.3
go1.17-1.17.2-1.6.2
go1.17-doc-1.17.2-1.6.2
go1.17-race-1.17.2-1.6.2
Ссылки
- E-Mail link for openSUSE-SU-2021:3488-1
- SUSE Security Ratings
- SUSE Bug 1190649
- SUSE Bug 1191468
- SUSE CVE CVE-2021-38297 page
Описание
Go before 1.16.9 and 1.17.x before 1.17.2 has a Buffer Overflow via large arguments in a function invocation from a WASM module, when GOARCH=wasm GOOS=js is used.
Затронутые продукты
openSUSE Leap 15.3:go1.17-1.17.2-1.6.2
openSUSE Leap 15.3:go1.17-doc-1.17.2-1.6.2
openSUSE Leap 15.3:go1.17-race-1.17.2-1.6.2
Ссылки
- CVE-2021-38297
- SUSE Bug 1191468
- SUSE Bug 1206559
- SUSE Bug 1208723