summary |
shortlog | log |
commit |
commitdiff |
tree
first ⋅ prev ⋅ next
Sylvain Beucler [Tue, 26 Apr 2022 17:32:45 +0000 (18:32 +0100)]
golang-1.7 (1.7.4-2+deb9u5) stretch-security; urgency=high
* Non-maintainer upload by the LTS Security Team.
* CVE-2022-23772: Rat.SetString in math/big has an overflow that can
lead to Uncontrolled Memory Consumption.
* CVE-2022-23806: Curve.IsOnCurve in crypto/elliptic can incorrectly
return true in situations with a big.Int value that is not a valid
field element.
* CVE-2022-24921: regexp.Compile allows stack exhaustion via a deeply
nested expression.
[dgit import unpatched golang-1.7 1.7.4-2+deb9u5]
Sylvain Beucler [Tue, 26 Apr 2022 17:32:45 +0000 (18:32 +0100)]
Import golang-1.7_1.7.4-2+deb9u5.debian.tar.xz
[dgit import tarball golang-1.7 1.7.4-2+deb9u5 golang-1.7_1.7.4-2+deb9u5.debian.tar.xz]
Tianon Gravi [Fri, 2 Dec 2016 21:30:36 +0000 (21:30 +0000)]
Import golang-1.7_1.7.4.orig.tar.gz
[dgit import orig golang-1.7_1.7.4.orig.tar.gz]