Oval Definition:oval:org.opensuse.security:def:111474
Revision Date:2021-07-01Version:1
Title:Security update for go1.15 (Important)
Description:

This update for go1.15 fixes the following issues:

Update to 1.15.13. Includes these security fixes

- CVE-2021-33195: net: Lookup functions may return invalid host names (bsc#1187443). - CVE-2021-33196: archive/zip: malformed archive may cause panic or memory exhaustion (bsc#1186622). - CVE-2021-33197: net/http/httputil: ReverseProxy forwards Connection headers if first one is empty (bsc#1187444) - CVE-2021-33198: math/big: (*Rat).SetString with '1.770p02041010010011001001' crashes with 'makeslice: len out of range' (bsc#1187445).

This update was imported from the SUSE:SLE-15:Update update project.
Family:unixClass:patch
Status:Reference(s):1175132
1186622
1187443
1187444
1187445
CVE-2021-33195
CVE-2021-33196
CVE-2021-33197
CVE-2021-33198
openSUSE-SU-2021:0950-1
Platform(s):openSUSE Leap 15.2
Product(s):
Definition Synopsis
  • openSUSE Leap 15.2 is installed
  • AND Package Information
  • go1.15-1.15.13-lp152.20.1 is installed
  • OR go1.15-doc-1.15.13-lp152.20.1 is installed
  • OR go1.15-race-1.15.13-lp152.20.1 is installed
  • BACK