Alerts This Week
Warning Icon 1 727
Alerts This Week
Warning Icon 1 727

Mageia 9: 2025-0021 critical: golang UDP header and URI bypass

mageia
Calendar Grey January 23, 2025
Dist Mageia Esm H88
Mageia 2025-0021 resolves essential security issues in golang pertaining to cross-site vulnerabilities and name restrictions. Discover more!
net/http: sensitive headers incorrectly sent after cross-domain redirect, (CVE-2024-45336)

Summary

net/http: sensitive headers incorrectly sent after cross-domain redirect, (CVE-2024-45336). crypto/x509: usage of IPv6 zone IDs can bypass URI name constraints, (CVE-2024-45341).

References

- https://bugs.mageia.org/show_bug.cgi?id=33940

- https://www.openwall.com/lists/oss-security/2025/01/17/1

- https://www.cve.org/CVERecord?id=CVE-2024-45336

- https://www.cve.org/CVERecord?id=CVE-2024-45341

Resolution

SRPMS

- 9/core/golang-1.22.11-1.mga9

Severity
critical
Lowest
Low
Medium
High
Critical

Publication date: 23 Jan 2025
URL: https://advisories.mageia.org/MGASA-2025-0021.html
Type: security
CVE: CVE-2024-45336, CVE-2024-45341

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here