Alerts This Week
Warning Icon 1 727
Alerts This Week
Warning Icon 1 727

Debian 10: DLA-3395-1 Moderate: golang-1.11 DoS And Code Execution

debian lts
Calendar Grey April 19, 2023
Dist Debian Esm H88
Enhance golang-1.11 to mitigate various security risks, including denial of service (DoS) and potential code execution vulnerabilities discovered within the Go programming language.
Multiple vulnerabilities were discovered in the Go programming language

Summary

CVE-2020-28367

Code injection in the go command with cgo allows arbitrary code
execution at build time via malicious gcc flags specified via a
#cgo directive.

CVE-2021-33196

In archive/zip, a crafted file count (in an archive''s header) can
cause a NewReader or OpenReader panic.

CVE-2021-36221

Go has a race condition that can lead to a net/http/httputil
ReverseProxy panic upon an ErrAbortHandler abort.

CVE-2021-38297

Go has a Buffer Overflow via large arguments in a function
invocation from a WASM module, when GOARCH=wasm GOOS=js is used.

CVE-2021-39293

This issue exists because of an incomplete fix for CVE-2021-33196.

CVE-2021-41771

ImportedSymbols in debug/macho (for Open or OpenFat) Accesses a
Memory Location After the End of a Buffer, aka an out-of-bounds
slice situation.

CVE-2021-44716

net/http allows uncontrolled memory consumption in the header
canonicalization cache via HTTP/2 requests.

CVE-2021-44717

Read the Full Advisory


Package: golang-1.11
Version: 1.11.6-1+deb10u6
CVE ID: CVE-2020-28367 CVE-2021-33196 CVE-2021-36221 CVE-2021-38297
Debian Bug: 989492 991961

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here