Alerts This Week
Warning Icon 1 764
Alerts This Week
Warning Icon 1 764

SUSE: 2020:3368-1 Moderate: go1.15 Remote Code Execution Issues

suse
Calendar Grey November 19, 2020
Dist Suse Esm H88
SUSE Security Patch for go1.16 addresses various vulnerabilities, encompassing severe remote code execution bugs and system updates.
An update that solves three vulnerabilities and has one errata is now available

Summary

This update for go1.15 fixes the following issues: - go1.15.5 (released 2020-11-12) includes security fixes to the cmd/go and math/big packages. * go#42553 math/big: panic during recursive division of very large numbers (bsc#1178750 CVE-2020-28362) * go#42560 cmd/go: arbitrary code can be injected into cgo generated files (bsc#1178752 CVE-2020-28367) * go#42557 cmd/go: improper validation of cgo flags can lead to remote code execution at build time (bsc#1178753 CVE-2020-28366) * go#42169 cmd/compile, runtime, reflect: pointers to go:notinheap types must be stored indirectly in interfaces * go#42151 cmd/cgo: opaque struct pointers are broken since Go 1.15.3 * go#42138 time: Location interprets wrong timezone (DST) with slim zoneinfo * go#42113 x/net/http2: the first write error on a connection will cause

References

#1175132 #1178750 #1178752 #1178753

Cross- CVE-2020-28362 CVE-2020-28366 CVE-2020-28367

Affected Products:

SUSE Linux Enterprise Module for Development Tools 15-SP2

SUSE Linux Enterprise Module for Development Tools 15-SP1

https://www.suse.com/security/cve/CVE-2020-28362.html

https://www.suse.com/security/cve/CVE-2020-28366.html

https://www.suse.com/security/cve/CVE-2020-28367.html

https://bugzilla.suse.com/1175132

https://bugzilla.suse.com/1178750

https://bugzilla.suse.com/1178752

https://bugzilla.suse.com/1178753

Announcement ID: SUSE-SU-2020:3368-1
Rating: moderate

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here