[SECURITY] [DSA 4503-1] golang-1.11 security update

Moritz Muehlenhoff <[email protected]>
Newsgroups gmane.comp.security.bugtraq
Message-ID <20190818182511.zflu2hemxwhmtiad__20047.3262158752$1566199822$gmane$org@seger.debian.org>
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

- -------------------------------------------------------------------------
Debian Security Advisory DSA-4503-1                   [email protected]
https://www.debian.org/security/                       Moritz Muehlenhoff
August 18, 2019                       https://www.debian.org/security/faq
- -------------------------------------------------------------------------

Package        : golang-1.11
CVE ID         : CVE-2019-9512 CVE-2019-9514 CVE-2019-14809

Three vulnerabilities have been discovered in the Go programming language;
"net/url" accepted some invalid hosts in URLs which could result in
authorisation bypass in some applications and the HTTP/2 implementation
was susceptible to denial of service.

For the stable distribution (buster), these problems have been fixed in
version 1.11.6-1+deb10u1.

We recommend that you upgrade your golang-1.11 packages.

For the detailed security status of golang-1.11 please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/golang-1.11

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/

Mailing list: [email protected]
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEtuYvPRKsOElcDakFEMKTtsN8TjYFAl1ZlroACgkQEMKTtsN8
TjZChQ//Vz4y63s3LD3Vz7oJLjchohCR9kHInoJcLM09osvIwBvi5rl/MnsEPUpP
8aMsDt50fZk/YhWSWQsmMCIQT+5CtjUOVbYnThHY5Hy+TpfgwVfe4JHIui5SEqDt
7K0VH7lIgkAncQc+wFzZALwPC+FgkZWyUk/4RuVXybiO8RgB9NMIXANl8PRK47b0
GxKJDT/Q84lksxhrFV0ib34+IPbF3mKAkxwx0FR9COEDBxBxKSQshY+imjtFo2NG
YHgwXyGuR9zOcyR8ObTsYaXOPQj8Kd/XZCeWN97Ii6UHWrSG4PvhjQzJfeV/NmJc
+kUfM7jzvg8PcGptOLPgbMlMt+XDwNwmPQC54RNyIv36OiYquMZSss3TweL2NV3Y
z/1CqG0A4qx9/KqZcgEpIOTgeyUc7LHgO8WEWkS5QcozWxaWC9/RoJZQ8spG5Ztd
leeDkzxkBSFoJJ3PBVRWGwzCMB7z6ePegw+/X4zdtBjQTb9TRMI0aj3MUyXOykrC
NkEj+QgAdZ8B9sIhke4gCEnvbsx5+L8lyVVZsVQ7yIgklXyMXwXqRKANtVAWVEU+
1367B1bGAxYfRWhE+HlAX6e6aKMyqRWi6/jb55MxOq3KTAljcIxSBZVBU+6Tpcd+
C5nG/4ox6oKlJMjOLt5/lWPiN2OVm0iJkyF154M9JjXKAz35gAk=
=5Pta
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.