[Git][security-tracker-team/security-tracker][master] CVE-2022-30630/golang: introduced in 1.16

Sylvain Beucler (@beuc) beuc at debian.org
Wed Sep 14 18:43:27 BST 2022



Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker


Commits:
50c4c9b8 by Sylvain Beucler at 2022-09-14T19:42:52+02:00
CVE-2022-30630/golang: introduced in 1.16

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -26415,12 +26415,12 @@ CVE-2022-30630 (Uncontrolled recursion in Glob in io/fs before Go 1.17.12 and Go
 	- golang-1.18 1.18.4-1
 	- golang-1.17 1.17.13-1
 	- golang-1.15 <removed>
-	- golang-1.11 <removed>
-	[buster] - golang-1.11 <no-dsa> (Limited support)
 	NOTE: https://go.dev/issue/53415
 	NOTE: https://github.com/golang/go/commit/fa2d41d0ca736f3ad6b200b2a4e134364e9acc59 (go1.19rc2)
 	NOTE: https://github.com/golang/go/commit/315e80d293b684ac2902819e58f618f1b5a14d49 (go1.18.4)
 	NOTE: https://github.com/golang/go/commit/8c1d8c836270615cfb5b229932269048ef59ac07 (go1.17.12)
+	NOTE: Introduced by https://github.com/golang/go/commit/b64202bc29b9c1cf0118878d1c0acc9cdb2308f6 (go1.16beta1)
+	NOTE: io/fs/Glob.go introduced in 1.16; see CVE-2022-30632 for similar older code in path/filepath/
 CVE-2022-30629 (Non-random values for ticket_age_add in session tickets in crypto/tls  ...)
 	- golang-1.18 1.18.3-1
 	- golang-1.17 1.17.11-1



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/50c4c9b854212249d80efd2bfe0361146d3c947e

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/50c4c9b854212249d80efd2bfe0361146d3c947e
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20220914/e6756b4b/attachment.htm>


More information about the debian-security-tracker-commits mailing list