summary |
shortlog | log |
commit |
commitdiff |
tree
first ⋅ prev ⋅ next
Thorsten Alteholz [Fri, 20 Nov 2020 16:03:02 +0000 (16:03 +0000)]
golang-1.7 (1.7.4-2+deb9u2) stretch-security; urgency=high
* Non-maintainer upload by the LTS Team.
* CVE-2020-15586
Using the 100-continue in HTTP headers received by a net/http/Server
can lead to a data race involving the connection's buffered writer.
* CVE-2020-16845
Certain invalid inputs to ReadUvarint or ReadVarint could cause those
functions to read an unlimited number of bytes from the ByteReader
argument before returning an error.
[dgit import unpatched golang-1.7 1.7.4-2+deb9u2]
Thorsten Alteholz [Fri, 20 Nov 2020 16:03:02 +0000 (16:03 +0000)]
Import golang-1.7_1.7.4-2+deb9u2.debian.tar.xz
[dgit import tarball golang-1.7 1.7.4-2+deb9u2 golang-1.7_1.7.4-2+deb9u2.debian.tar.xz]
Tianon Gravi [Fri, 2 Dec 2016 21:30:36 +0000 (21:30 +0000)]
Import golang-1.7_1.7.4.orig.tar.gz
[dgit import orig golang-1.7_1.7.4.orig.tar.gz]