golang-1.7 (1.7.4-2+deb9u5) stretch-security; urgency=high
authorSylvain Beucler <beuc@debian.org>
Tue, 26 Apr 2022 17:32:45 +0000 (18:32 +0100)
committerSylvain Beucler <beuc@debian.org>
Tue, 26 Apr 2022 17:32:45 +0000 (18:32 +0100)
commitff1172b7d623a286e6b0da76fbbfcc0b32f8cf47
tree101f96d048a2badfcbed881de648a7ba51eef461
parent58431a76751d1c93469f501ba36a5a04259f100d
parentd6b414ba468748494c2a8dd4340e67b4a55b06c2
golang-1.7 (1.7.4-2+deb9u5) stretch-security; urgency=high

  * Non-maintainer upload by the LTS Security Team.
  * CVE-2022-23772: Rat.SetString in math/big has an overflow that can
    lead to Uncontrolled Memory Consumption.
  * CVE-2022-23806: Curve.IsOnCurve in crypto/elliptic can incorrectly
    return true in situations with a big.Int value that is not a valid
    field element.
  * CVE-2022-24921: regexp.Compile allows stack exhaustion via a deeply
    nested expression.

[dgit import unpatched golang-1.7 1.7.4-2+deb9u5]