golang-1.13 (1.13.7-1) unstable; urgency=medium
authorDr. Tobias Quathamer <toddy@debian.org>
Fri, 31 Jan 2020 20:47:40 +0000 (20:47 +0000)
committerDr. Tobias Quathamer <toddy@debian.org>
Fri, 31 Jan 2020 20:47:40 +0000 (20:47 +0000)
commit619a2a1e3234fcfebd15b32e69ab2e691137e145
treeb28a47decc8d4adb25315bb281b4a011bc7ad7ae
parente02930e3a23ff52e35f8d673d84031be9357180f
parent16906ac9d4e6d779af406f9d6ddcb5a9b7f80ad7
golang-1.13 (1.13.7-1) unstable; urgency=medium

  * New upstream version 1.13.7
    - cryptobyte: fix panic due to malformed ASN.1 inputs on 32-bit archs.
      When int is 32 bits wide (on 32-bit architectures like 386 and arm),
      an overflow could occur, causing a panic, due to malformed ASN.1
      being passed to any of the ASN1 methods of String.
      This fixes CVE-2020-7919 and was found thanks to the
      Project Wycheproof test vectors.
  * Update upstream's signing key

[dgit import unpatched golang-1.13 1.13.7-1]
29 files changed:
debian/changelog
debian/control
debian/control.in
debian/copyright
debian/docs
debian/gbp.conf
debian/gbp.conf.in
debian/golang-X.Y-doc.dirs
debian/golang-X.Y-doc.install
debian/golang-X.Y-doc.links
debian/golang-X.Y-doc.lintian-overrides
debian/golang-X.Y-go.dirs
debian/golang-X.Y-go.install
debian/golang-X.Y-go.links
debian/golang-X.Y-go.lintian-overrides
debian/golang-X.Y-go.postinst
debian/golang-X.Y-src.install
debian/golang-X.Y-src.lintian-overrides
debian/helpers/goenv.sh
debian/patches/0001-Disable-test-for-UserHomeDir.patch
debian/patches/0002-Fix-Lintian-warnings-about-wrong-interpreter-path.patch
debian/patches/series
debian/rules
debian/source/format
debian/source/lintian-overrides
debian/source/lintian-overrides.in
debian/upstream/signing-key.asc
debian/watch
debian/watch.in