Alerts This Week
Warning Icon 1 626
Alerts This Week
Warning Icon 1 626

openSUSE: 2020:2047-1 Moderate: go1.14 Remote Code Execution

opensuse
Calendar Grey November 26, 2020
Dist Opensuse Esm H88
openSUSE issues security notice for go1.14, tackling various vulnerabilities and offering guidance on how to update.
An update that solves three vulnerabilities and has one errata is now available.

Description

This update for go1.14 fixes the following issues:

- go1.14.12 (released 2020-11-12) includes security fixes to the cmd/go

and math/big packages.

* go#42553 math/big: panic during recursive division of very large

numbers (bsc#1178750 CVE-2020-28362)

* go#42560 cmd/go: arbitrary code can be injected into cgo generated

files (bsc#1178752 CVE-2020-28367)

* go#42557 cmd/go: improper validation of cgo flags can lead to remote

code execution at build time (bsc#1178753 CVE-2020-28366)

* go#42155 time: Location interprets wrong timezone (DST) with slim

zoneinfo

* go#42112 x/net/http2: the first write error on a connection will cause

all subsequent write requests to fail blindly

* go#41991 runtime: macOS-only segfault on 1.14+ with "split stack

overflow"

* go#41913 net/http: request.Clone doesn't deep copy TransferEncoding

* go#41703 runtime: macOS syscall.Exec can get SIGILL due to...

Read the Full Advisory

Patch

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Leap 15.1:

zypper in -t patch openSUSE-2020-2047=1

Package List

- openSUSE Leap 15.1 (x86_64):

go1.14-1.14.12-lp151.22.1

go1.14-doc-1.14.12-lp151.22.1

go1.14-race-1.14.12-lp151.22.1

References

https://www.suse.com/security/cve/CVE-2020-28362.html

https://www.suse.com/security/cve/CVE-2020-28366.html

https://www.suse.com/security/cve/CVE-2020-28367.html

https://bugzilla.suse.com/1164903

https://bugzilla.suse.com/1178750

https://bugzilla.suse.com/1178752

https://bugzilla.suse.com/1178753

openSUSE Security Announce mailing list -- security-announce@lists.opensuse.org

To unsubscribe, email security-announce-leave@lists.opensuse.org

List Netiquette:

List Archives:

Announcement ID: openSUSE-SU-2020:2047-1
Rating: moderate
Affected Products: openSUSE Leap 15.1 e.

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here