golang-1.15 (1.15.9-5) unstable; urgency=medium
authorShengjing Zhu <zhsj@debian.org>
Sat, 5 Jun 2021 11:36:34 +0000 (12:36 +0100)
committerShengjing Zhu <zhsj@debian.org>
Sat, 5 Jun 2021 11:36:34 +0000 (12:36 +0100)
commit03c32cb9d93d28a21e19f6608f61479ac402bffc
tree4e0191a86f1b0d72db7dd5196c38e57e911ca6f9
parent77a602187230fbc1e758d87961410e94a6005e59
parent74b8bc14e77900382c1ada52f7c4b52973dee1b8
golang-1.15 (1.15.9-5) unstable; urgency=medium

  * Team upload.
  * Backport patches for CVE-2021-33195 CVE-2021-33197 CVE-2021-33198
    + CVE-2021-33195: net: Lookup functions may return invalid host names
    + CVE-2021-33197: net/http/httputil: ReverseProxy forwards Connection
      headers if first one is empty
    + CVE-2021-33198: math/big: (*Rat).SetString with "1.770p02041010010011001001"
      crashes with "makeslice: len out of range"

[dgit import unpatched golang-1.15 1.15.9-5]
39 files changed:
debian/changelog
debian/control
debian/control.in
debian/copyright
debian/docs
debian/gbp.conf
debian/gbp.conf.in
debian/golang-X.Y-doc.dirs
debian/golang-X.Y-doc.install
debian/golang-X.Y-doc.links
debian/golang-X.Y-doc.lintian-overrides
debian/golang-X.Y-go.dirs
debian/golang-X.Y-go.install
debian/golang-X.Y-go.links
debian/golang-X.Y-go.lintian-overrides
debian/golang-X.Y-go.postinst
debian/golang-X.Y-src.install
debian/golang-X.Y-src.lintian-overrides
debian/helpers/goenv.sh
debian/patches/0001-Disable-test-for-UserHomeDir.patch
debian/patches/0002-Fix-Lintian-warnings-about-wrong-interpreter-path.patch
debian/patches/0003-cmd-go-cmd-cgo-pass-mfp32-and-mhard-soft-float-to-MI.patch
debian/patches/0004-cmd-dist-fix-build-failure-of-misc-cgo-test-on-arm64.patch
debian/patches/0005-cmd-dist-increase-default-timeout-scale-for-arm.patch
debian/patches/0006-skip-userns-test-in-schroot-as-well.patch
debian/patches/0007-CVE-2021-31525.patch
debian/patches/0008-CVE-2021-33196.patch
debian/patches/0009-CVE-2021-33195-1.patch
debian/patches/0010-CVE-2021-33195-2.patch
debian/patches/0011-CVE-2021-33197.patch
debian/patches/0012-CVE-2021-33198.patch
debian/patches/series
debian/rules
debian/source/format
debian/source/lintian-overrides
debian/source/lintian-overrides.in
debian/upstream/signing-key.asc
debian/watch
debian/watch.in