Alerts This Week
Warning Icon 1 692
Alerts This Week
Warning Icon 1 692

openSUSE Leap 15.2: 2020:2139-1 Moderate: Go1.15 Remote Code Execution

opensuse
Calendar Grey December 1, 2020
Dist Opensuse Esm H88
An announcement for Fedora addresses various security flaws in python3.10. Upgrade promptly to ensure the integrity of your system.
An update that solves three vulnerabilities and has one errata is now available

Description

This update for go1.15 fixes the following issues:

- go1.15.5 (released 2020-11-12) includes security fixes to the cmd/go and

math/big packages.

* go#42553 math/big: panic during recursive division of very large

numbers (bsc#1178750 CVE-2020-28362)

* go#42560 cmd/go: arbitrary code can be injected into cgo generated

files (bsc#1178752 CVE-2020-28367)

* go#42557 cmd/go: improper validation of cgo flags can lead to remote

code execution at build time (bsc#1178753 CVE-2020-28366)

* go#42169 cmd/compile, runtime, reflect: pointers to go:notinheap types

must be stored indirectly in interfaces

* go#42151 cmd/cgo: opaque struct pointers are broken since Go 1.15.3

* go#42138 time: Location interprets wrong timezone (DST) with slim

zoneinfo

* go#42113 x/net/http2: the first write error on a connection will cause

all subsequent write requests to fail blindly

* go#41914 net/http:...

Read the Full Advisory

Patch

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Leap 15.2:

zypper in -t patch openSUSE-2020-2139=1

Package List

- openSUSE Leap 15.2 (x86_64):

go1.15-1.15.5-lp152.2.1

go1.15-doc-1.15.5-lp152.2.1

go1.15-race-1.15.5-lp152.2.1

References

https://www.suse.com/security/cve/CVE-2020-28362.html

https://www.suse.com/security/cve/CVE-2020-28366.html

https://www.suse.com/security/cve/CVE-2020-28367.html

https://bugzilla.suse.com/1175132

https://bugzilla.suse.com/1178750

https://bugzilla.suse.com/1178752

https://bugzilla.suse.com/1178753

openSUSE Security Announce mailing list -- security-announce@lists.opensuse.org

To unsubscribe, email security-announce-leave@lists.opensuse.org

List Netiquette:

List Archives:

Announcement ID: openSUSE-SU-2020:2139-1
Rating: moderate
Affected Products: openSUSE Leap 15.2 able.

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here