Alerts This Week
Warning Icon 1 700
Alerts This Week
Warning Icon 1 700

Fedora 21: 2015-12957 Critical: Golang HTTP Request Smuggling

fedora
Calendar Grey August 18, 2015
Dist Fedora Esm H88
Important security patch released for Fedora 21 golang, focusing on vulnerabilities related to malicious HTTP request manipulation. Safeguard your system now.
security fixes for net/http smuggling

Summary

The Go Programming Language.

Update Information:

security fixes for net/http smuggling

Change Log

* Wed Aug 5 2015 Vincent Batts - 1.4.2-3 - bz1250352 * Wed Mar 18 2015 Vincent Batts - 1.4.2-2 - obsoleting deprecated packages * Wed Feb 18 2015 Vincent Batts - 1.4.2-1 - updating to go1.4.2 * Fri Jan 16 2015 Vincent Batts - 1.4.1-1 - updating to go1.4.1 * Fri Jan 2 2015 Vincent Batts - 1.4-2 - doc organizing * Thu Dec 11 2014 Vincent Batts - 1.4-1 - update to go1.4 release * Wed Dec 3 2014 Vincent Batts - 1.3.99-3.1.4rc2 - update to go1.4rc2 * Mon Nov 17 2014 Vincent Batts - 1.3.99-2.1.4rc1 - update to go1.4rc1 * Thu Oct 30 2014 Vincent Batts - 1.3.99-1.1.4beta1 - update to go1.4beta1 * Thu Oct 30 2014 Vincent Batts - 1.3.3-3 - macros will need to be in their own rpm * Fri Oct 24 2014 Vincent Batts - 1.3.3-2 - split out rpm macros (bz1156129) - progress on gccgo accomodation

References


[ 1 ] Bug #1250352 - CVE-2015-5739 CVE-2015-5740 CVE-2015-5741 golang: HTTP request smuggling in net/http library https://bugzilla.redhat.com/show_bug.cgi?id=1250352

Update Instructions

This update can be installed with the "yum" update program. Use su -c 'yum update golang' at the command line. For more information, refer to "Managing Software with yum", available at .

Severity
critical
Lowest
Low
Medium
High
Critical

Name: golang
Product: Fedora 21
Version: 1.4.2
Release: 3.fc21
Summary: The Go Programming Language

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here