Revision Date: | 2019-08-23 | Version: | 1 |
Title: | Security update for go1.11 (Moderate) |
Description: |
This update for go1.11 fixes the following issues:
Security issues fixed:
- CVE-2019-9512: Fixed HTTP/2 flood using PING frames that results in unbounded memory growth (bsc#1146111). - CVE-2019-9514: Fixed HTTP/2 implementation that is vulnerable to a reset flood, potentially leading to a denial of service (bsc#1146115). - CVE-2019-14809: Fixed malformed hosts in URLs that leads to authorization bypass (bsc#1146123).
Bugfixes:
- Update to go version 1.11.13 (bsc#1141688).
|
Family: | unix | Class: | patch |
Status: | | Reference(s): | 1141688 1146111 1146115 1146123 CVE-2019-14809 CVE-2019-9512 CVE-2019-9514 SUSE-SU-2019:2213-1
|
Platform(s): | SUSE Linux Enterprise Module for Open Buildservice Development Tools 15 SP1
| Product(s): | |