[Forgot Password]
Login  Register Subscribe

30481

 
 

423868

 
 

255116

 
 

909

 
 

198683

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

RLSA-2022:1819 --- golang

ID: oval:org.secpod.oval:def:4500895Date: (C)2023-04-03   (M)2023-12-11
Class: PATCHFamily: unix




Go Toolset provides the Go programming language tools and libraries. Go is alternatively known as golang. Security Fix: * golang: Command-line arguments may overwrite global data * golang: archive/zip: malformed archive may cause panic or memory exhaustion * golang: debug/macho: invalid dynamic symbol table command can cause panic * golang: archive/zip: Reader.Open panics on empty string * golang: math/big: uncontrolled memory consumption due to an unhandled overflow via Rat.SetString * golang: cmd/go: misinterpretation of branch names can lead to incorrect access control * golang: crypto/elliptic IsOnCurve returns true for invalid field elements For more details about the security issue, including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page listed in the References section. Additional Changes: For detailed information on changes in this release, see the Rocky Linux 8.6 Release Notes linked from the References section.

Platform:
Rocky Linux 8
Product:
golang
delve
go-toolset
Reference:
RLSA-2022:1819
CVE-2021-38297
CVE-2021-39293
CVE-2021-41771
CVE-2021-41772
CVE-2022-23772
CVE-2022-23773
CVE-2022-23806
CVE    7
CVE-2021-38297
CVE-2021-39293
CVE-2021-41771
CVE-2021-41772
...
CPE    3
cpe:/a:golang:golang
cpe:/a:go-delve:golang
cpe:/a:golang:go-toolset

© SecPod Technologies