Alerts This Week
Warning Icon 1 626
Alerts This Week
Warning Icon 1 626

openSUSE Leap 15.2: 2020:1587-1 Moderate: Go1.14 Cross-Site Scripting

opensuse
Calendar Grey October 1, 2020
Dist Opensuse Esm H88
This Fedora patch resolves a vulnerability in ruby2.7, delivering crucial corrections and update information.
An update that solves one vulnerability and has one errata is now available.

Description

This update for go1.14 fixes the following issues:

- go1.14.9 (released 2020-09-09) includes fixes to the compiler, linker,

runtime, documentation, and the net/http and testing packages. Refs

bsc#1164903 go1.14 release tracking

* go#41192 net/http/fcgi: race detected during execution of

TestResponseWriterSniffsContentType test

* go#41016 net/http: Transport.CancelRequest no longer cancels in-flight

request

* go#40973 net/http: RoundTrip unexpectedly changes Request

* go#40968 runtime: checkptr incorrectly -race flagging when using &^

arithmetic

* go#40938 cmd/compile: R12 can be clobbered for write barrier call on

PPC64

* go#40848 testing: "=== PAUSE" lines do not change the test name for

the next log line

* go#40797 cmd/compile: inline marker targets not reachable after

assembly on arm

* go#40766 cmd/compile: inline marker targets not reachable after

assembly on ppc64x

*...

Read the Full Advisory

Patch

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Leap 15.2:

zypper in -t patch openSUSE-2020-1587=1

Package List

- openSUSE Leap 15.2 (x86_64):

go1.14-1.14.9-lp152.2.6.1

go1.14-doc-1.14.9-lp152.2.6.1

go1.14-race-1.14.9-lp152.2.6.1

References

https://www.suse.com/security/cve/CVE-2020-24553.html

https://bugzilla.suse.com/1164903

https://bugzilla.suse.com/1176031

--

Announcement ID: openSUSE-SU-2020:1587-1
Rating: moderate
Affected Products: openSUSE Leap 15.2 le.

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here