[Git][security-tracker-team/security-tracker][master] CVE-2020-28367/golang: reference patch and regression fix
Sylvain Beucler (@beuc)
beuc at debian.org
Fri Apr 14 22:40:24 BST 2023
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker
Commits:
59ccb3a7 by Sylvain Beucler at 2023-04-14T23:40:03+02:00
CVE-2020-28367/golang: reference patch and regression fix
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -185663,6 +185663,8 @@ CVE-2020-28367 (Code injection in the go command with cgo before Go 1.14.12 and
[stretch] - golang-1.7 <ignored> (validation of cgo flags first introduced in golang-1.8 / CVE-2018-6574)
NOTE: https://groups.google.com/g/golang-announce/c/NpBGTTmKzpM/m/fLguyiM2CAAJ
NOTE: https://github.com/golang/go/issues/42556
+ NOTE: Fixed by: https://github.com/golang/go/commit/da7aa86917811a571e6634b45a457f918b8e6561 (go1.16beta1)
+ NOTE: Regression: https://github.com/golang/go/commit/782cf560db4c919790fdb476d1bbe18e5ddf5ffd (go1.16beta1)
CVE-2020-28366 (Code injection in the go command with cgo before Go 1.14.12 and Go 1.1 ...)
- golang-1.15 1.15.5-1
- golang-1.11 <removed>
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/59ccb3a7b06612f1a72f679f50943f3bf5eaca52
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/59ccb3a7b06612f1a72f679f50943f3bf5eaca52
You're receiving this email because of your account on salsa.debian.org.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20230414/d26d06a6/attachment.htm>
More information about the debian-security-tracker-commits
mailing list