/[advisories]/29526.adv
ViewVC logotype

Contents of /29526.adv

Parent Directory Parent Directory | Revision Log Revision Log


Revision 12603 - (show annotations) (download)
Wed Oct 13 19:10:55 2021 UTC (2 years, 6 months ago) by tmb
File size: 1200 byte(s)
MGASA-2021-0475: golang-1.17.2-1.mga8
1 type: security
2 subject: Updated golang packages fix security vulnerability
3 CVE:
4 - CVE-2021-39293
5 - CVE-2021-38297
6 src:
7 8:
8 core:
9 - golang-1.17.2-1.mga8
10 description: |
11 The fix for CVE-2021-33196 can be bypassed by crafted inputs. As a result,
12 the NewReader and OpenReader functions in archive/zip can still cause a
13 panic or an unrecoverable fatal error when reading an archive that claims
14 to contain a large number of files, regardless of its actual size.
15 (CVE-2021-39293)
16 A security issue has been found in go before version 1.17.2. When invoking
17 functions from WASM modules, built using GOARCH=wasm GOOS=js, passing very
18 large arguments can cause portions of the module to be overwritten with
19 data from the arguments. (CVE-2021-38297)
20 references:
21 - https://bugs.mageia.org/show_bug.cgi?id=29526
22 - https://groups.google.com/g/golang-announce/c/dx9d7IOseHw
23 - https://groups.google.com/g/golang-announce/c/7efr4VBoZIw
24 - https://groups.google.com/g/golang-announce/c/AEBu9j7yj5A
25 - https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/5EY52N4KALEDKULS6YHUPW2C7OJTGHTS/
26 - https://security.archlinux.org/CVE-2021-38297
27 ID: MGASA-2021-0475

  ViewVC Help
Powered by ViewVC 1.1.30