golang-1.21 (1.21.8-1) unstable; urgency=medium
authorShengjing Zhu <zhsj@debian.org>
Wed, 6 Mar 2024 07:14:10 +0000 (15:14 +0800)
committerShengjing Zhu <zhsj@debian.org>
Wed, 6 Mar 2024 07:14:10 +0000 (15:14 +0800)
commitade6318f676f3a565f1a1bfef081ac9a4923a087
tree43f6fe8077ed08a93c205eb8b86ce433bfa8411a
parent928b3652add067226b94609b52d56dd5021d7ea0
parent962cf7a58b2889d0bfd7b5bebc381914dadfe778
golang-1.21 (1.21.8-1) unstable; urgency=medium

  * Team upload
  * New upstream version 1.21.8
    + CVE-2024-24783: crypto/x509: Verify panics on certificates with an
      unknown public key algorithm
    + CVE-2023-45290: net/http: memory exhaustion in Request.ParseMultipartForm
    + CVE-2023-45289: net/http, net/http/cookiejar: incorrect forwarding of
      sensitive headers and cookies on HTTP redirect
    + CVE-2024-24785: html/template: errors returned from MarshalJSON methods
      may break template escaping
    + CVE-2024-24784: net/mail: comments in display names are incorrectly
      handled
  * Update upstream signing key

[dgit import unpatched golang-1.21 1.21.8-1]
28 files changed:
debian/changelog
debian/control
debian/control.in
debian/copyright
debian/docs
debian/gbp.conf
debian/gbp.conf.in
debian/golang-X.Y-doc.dirs
debian/golang-X.Y-doc.install
debian/golang-X.Y-doc.links
debian/golang-X.Y-go.dirs
debian/golang-X.Y-go.install
debian/golang-X.Y-go.links
debian/golang-X.Y-go.lintian-overrides
debian/golang-X.Y-src.install
debian/golang-X.Y-src.lintian-overrides
debian/helpers/goenv.sh
debian/patches/0001-Skip-flaky-TestCrashDumpsAllThreads-on-mips64le.patch
debian/patches/series
debian/rules
debian/source/format
debian/source/lintian-overrides
debian/tests/control
debian/tests/hello-world
debian/tests/regression-test
debian/upstream/signing-key.asc
debian/watch
debian/watch.in