Alerts This Week
Warning Icon 1 692
Alerts This Week
Warning Icon 1 692

Mageia: 2021-0537 Critical Update for Golang Memory Access Issues

mageia
Calendar Grey December 3, 2021
Dist Mageia Esm H88
MGASA-2021-0538 tackles vulnerabilities identified in Python libraries, necessitating immediate updates for impacted modules in Mageia.
ImportedSymbols in debug/macho (for Open or OpenFat) in Go before 1.16.10 and 1.17.x before 1.17.3 Accesses a Memory Location After the End of a Buffer, aka an out-of-bounds slice ...

Summary

ImportedSymbols in debug/macho (for Open or OpenFat) in Go before 1.16.10 and 1.17.x before 1.17.3 Accesses a Memory Location After the End of a Buffer, aka an out-of-bounds slice situation. (CVE-2021-41771)

Go before 1.16.10 and 1.17.x before 1.17.3 allows an archive/zip Reader.Open panic via a crafted ZIP archive containing an invalid name or an empty filename field. (CVE-2021-41772)

References

- https://bugs.mageia.org/show_bug.cgi?id=29717

- https://lists.suse.com/pipermail/sle-security-updates/2021-December/009791.html

-

- https://www.cve.org/CVERecord?id=CVE-2021-41771

- https://www.cve.org/CVERecord?id=CVE-2021-41772

Resolution

SRPMS

- 8/core/golang-1.17.3-1.mga8

Severity
critical
Lowest
Low
Medium
High
Critical

Publication date: 03 Dec 2021
URL: https://advisories.mageia.org/MGASA-2021-0537.html
Type: security
CVE: CVE-2021-41771, CVE-2021-41772

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here