Описание
Security update for go-sendxmpp
This update for go-sendxmpp fixes the following issues:
Changes in go-sendxmpp:
- Update to 0.17.0:
- Add --ox-transfer-private-key to transfer the encrypted private key to PEP to transfer it to other devices (requires go-xmpp >= v0.3.7).
- Add --ox-receive-private-key to receive the encrypted private key from PEP.
- Add config option no_root_warning.
- Add config option no_legacy_pgp_warning.
- Also disable legacy PGP when running as root (Ox was already disabled).
- Disable pinning for not using PLAIN when running as root.
- Add config option ox_trust_mode with settings blind and tofu.
- Due to new tofu trust mode for Ox, only one public key per contact is accepted for easier ID handling.
- Ox: Check that fingerprint of received key equals the advertised one.
- CVE-2026-39821: Failure to reject ASCII-only Punycode-encoded labels allows for validation bypass and privilege escalation (bsc#1266617): Bump net to 0.57.0
Список пакетов
openSUSE Leap 16.0
go-sendxmpp-0.17.0-bp160.1.1
Ссылки
- SUSE Security Ratings
- SUSE Bug 1266617
- SUSE CVE CVE-2026-39821 page
Описание
The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode("xn--example-.com") incorrectly returns the name "example.com" rather than an error. This behavior can lead to privilege escalation in programs using the idna package. For example, a program which performs privilege checks on the ASCII hostname may reject "example.com" but permit "xn--example-.com". If that program subsequently converts the ASCII hostname to Unicode, it will inadvertently permits access to the Unicode name "example.com".
Затронутые продукты
openSUSE Leap 16.0:go-sendxmpp-0.17.0-bp160.1.1
Ссылки
- CVE-2026-39821
- SUSE Bug 1266474