golang-1.11 (1.11.6-1+deb10u4) buster-security; urgency=high
authorShengjing Zhu <zhsj@debian.org>
Sun, 24 Jan 2021 19:15:38 +0000 (19:15 +0000)
committerShengjing Zhu <zhsj@debian.org>
Sun, 24 Jan 2021 19:15:38 +0000 (19:15 +0000)
commit9ee495ac648596489dd8325d8104fdf410f6375f
tree8f07f4d29bdecb5747aede20d3181d7a504fafc4
parent9bf8eaf24c702460873dee06c667ef604e74db5d
parent293619570d43d2996e35fd3a3cf8055b400ba709
golang-1.11 (1.11.6-1+deb10u4) buster-security; urgency=high

  * Team upload.

  [ Dr. Tobias Quathamer ]
  * cryptobyte: fix panic due to malformed ASN.1 inputs on 32-bit archs
    https://github.com/golang/go/issues/36837
    CVE-2020-7919
  * net/http: Expect 100-continue panics in httputil.ReverseProxy
    https://github.com/golang/go/issues/34902
    CVE-2020-15586
  * encoding/binary: ReadUvarint and ReadVarint can read an unlimited
    number of bytes from invalid inputs
    https://github.com/golang/go/issues/40618
    CVE-2020-16845

  [ Shengjing Zhu ]
  * crypto/elliptic: incorrect operations on the P-224 curve
    https://github.com/golang/go/issues/43786
    CVE-2021-3114

[dgit import unpatched golang-1.11 1.11.6-1+deb10u4]
39 files changed:
debian/changelog
debian/compat
debian/control
debian/control.in
debian/copyright
debian/docs
debian/gbp.conf
debian/gbp.conf.in
debian/golang-X.Y-doc.dirs
debian/golang-X.Y-doc.install
debian/golang-X.Y-doc.links
debian/golang-X.Y-doc.lintian-overrides
debian/golang-X.Y-go.dirs
debian/golang-X.Y-go.install
debian/golang-X.Y-go.links
debian/golang-X.Y-go.lintian-overrides
debian/golang-X.Y-go.postinst
debian/golang-X.Y-src.install
debian/golang-X.Y-src.lintian-overrides
debian/helpers/goenv.sh
debian/patches/0001-Reproducible-BUILD_PATH_PREFIX_MAP.patch
debian/patches/0002-Fix-Lintian-warnings-about-wrong-interpreter-path.patch
debian/patches/0003-arm64-arm64asm-recognise-new-ssbb-pssbb-mnemonics-fr.patch
debian/patches/0004-fix-Fstatat-by-using-fillStat_t-on-linux-mips64x.patch
debian/patches/0005-Fix-CVE-2019-9512-and-CVE-2019-9514.patch
debian/patches/0006-Fix-CVE-2019-14809.patch
debian/patches/0007-Fix-CVE-2019-16276.patch
debian/patches/0008-Fix-CVE-2019-17596.patch
debian/patches/0009-Fix-CVE-2020-7919.patch
debian/patches/0010-Fix-CVE-2020-15586.patch
debian/patches/0011-Fix-CVE-2020-16845.patch
debian/patches/0012-Fix-CVE-2021-3114.patch
debian/patches/series
debian/rules
debian/source/format
debian/source/lintian-overrides
debian/source/lintian-overrides.in
debian/watch
debian/watch.in