Updated golang packages fix security vulnerability: Daniel Mandragona discovered that invalid DSA public keys can cause a panic in dsa.Verify(), resulting in denial of service (CVE-2019-17596). . MGASA-2019-0310 - Updated golang packages fix security vulnerability Publication date: 02 Nov 2019 URL: https://advisories.mageia.org/MGASA-2019-0310.html Type: security Affected Mageia releases: 7 CVE: CVE-2019-17596 Updated golang packages fix security vulnerability: Daniel Mandragona discovered that invalid DSA public keys can cause a panic in dsa.Verify(), resulting in denial of service (CVE-2019-17596). References: - https://bugs.mageia.org/show_bug.cgi?id=25616 - https://groups.google.com/forum/#!msg/golang-announce/lVEm7llp0w0/VbafyRkgCgAJ - https://lists.debian.org/debian-security-announce/2019/msg00203.html - https://www.cve.org/CVERecord?id=CVE-2019-17596 SRPMS: - 7/core/golang-1.12.11-1.mga7 . Revised Go libraries tackle service interruption caused by incorrect DSA key usage. Patch issued on November 2, 2019.. Golang Security Update, Mageia Advisory, DSA Key Vulnerability. . Severity: Critical. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.