[Git][security-tracker-team/security-tracker][master] 2 commits: CVE-2022-41716/go affects cross compile for Windows binary

Shengjing Zhu (@zhsj) zhsj at debian.org
Fri Apr 14 10:47:38 BST 2023



Shengjing Zhu pushed to branch master at Debian Security Tracker / security-tracker


Commits:
8f71d72e by Shengjing Zhu at 2023-04-14T17:46:30+08:00
CVE-2022-41716/go affects cross compile for Windows binary

See 29f7d181bd88e363de11541667af407043579f00 as well

- - - - -
0886e400 by Shengjing Zhu at 2023-04-14T17:46:31+08:00
CVE-2022-27664 affects golang-golang-x-net as well

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -47352,13 +47352,14 @@ CVE-2022-41717 (An attacker can cause excessive memory growth in a Go server acc
 	NOTE: https://github.com/golang/go/commit/76cad4edc29d28432a7a0aa27e87385d3d7db7a1 (go1.18.9)
 	NOTE: https://github.com/golang/net/commit/1e63c2f08a10a150fa02c50ece89b340ae64efe4
 CVE-2022-41716 (Due to unsanitized NUL values, attackers may be able to maliciously se ...)
-	- golang-1.19 <not-affected> (Only affects Go on Windows)
-	- golang-1.18 <not-affected> (Only affects Go on Windows)
-	- golang-1.15 <not-affected> (Only affects Go on Windows)
-	- golang-1.11 <not-affected> (Only affects Go on Windows)
+	- golang-1.19 1.19.3-1 (unimportant)
+	- golang-1.18 1.18.8-1 (unimportant)
+	- golang-1.15 <removed> (unimportant)
+	- golang-1.11 <removed> (unimportant)
 	NOTE: https://go.dev/issue/56284
 	NOTE: https://go.dev/cl/446916
 	NOTE: https://groups.google.com/g/golang-announce/c/mbHY1UY3BaM/m/hSpmRzk-AgAJ
+	NOTE: Only affects code cross compiled on Debian for Windows binaries
 CVE-2022-41715 (Programs which compile regular expressions from untrusted sources may  ...)
 	- golang-1.19 1.19.2-1
 	- golang-1.18 1.18.7-1
@@ -86557,10 +86558,13 @@ CVE-2022-27664 (In net/http in Go before 1.18.6 and 1.19.x before 1.19.1, attack
 	- golang-1.15 <removed>
 	- golang-1.11 <removed>
 	[buster] - golang-1.11 <postponed> (Limited support, minor issue, follow bullseye DSAs/point-releases)
+	- golang-golang-x-net 1:0.0+git20221012.0b7e1fb+dfsg-1
+	- golang-golang-x-net-dev <removed>
 	NOTE: https://groups.google.com/g/golang-announce/c/x49AQzIVX-s
 	NOTE: https://github.com/golang/go/issues/54658
 	NOTE: https://github.com/golang/go/commit/9cfe4e258b1c9d4a04a42539c21c7bdb2e227824 (go1.19.1)
 	NOTE: https://github.com/golang/go/commit/5bc9106458fc07851ac324a4157132a91b1f3479 (go1.18.6)
+	NOTE: https://github.com/golang/net/commit/f3363e06e74cdc304618bf31d898b78590103527
 CVE-2022-27663
 	RESERVED
 CVE-2022-27658 (Under certain conditions, SAP Innovation management - version 2.0, all ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/4368a220988d54b284fe189488479e017b633a52...0886e40041fcfb3242875a417097128e37578bab

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/4368a220988d54b284fe189488479e017b633a52...0886e40041fcfb3242875a417097128e37578bab
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20230414/b69b38e4/attachment.htm>


More information about the debian-security-tracker-commits mailing list