-
- Downloads
Import Debian changes 1.18.10-1~bpo11+1
golang-1.18 (1.18.10-1~bpo11+1) bullseye-backports; urgency=medium . * Rebuild for bullseye-backports. . golang-1.18 (1.18.10-1) unstable; urgency=medium . * Team upload. * New upstream version 1.18.10 * Add NO_PNG_PKG_MANGLE to prevent mangling testdata. This is Ubuntu specific behaviour so they can sync the package without vendor patch. . golang-1.18 (1.18.9-1) unstable; urgency=medium . * New upstream version 1.18.9 + CVE-2022-41720: os, net/http: avoid escapes from os.DirFS and http.Dir on Windows + CVE-2022-41717: net/http: limit canonical header cache by bytes, not entries . golang-1.18 (1.18.8-1~bpo11+1) bullseye-backports; urgency=medium . * Rebuild for bullseye-backports. . golang-1.18 (1.18.8-1) unstable; urgency=medium . * New upstream version 1.18.8 + CVE-2022-41716: syscall, os/exec: unsanitized NUL in environment variables On Windows, syscall.StartProcess and os/exec.Cmd did not properly check for invalid environment variable values. A malicious environment variable value could exploit this behavior to set a value for a different environment variable. . golang-1.18 (1.18.7-1) unstable; urgency=medium . * New upstream version 1.18.7 + CVE-2022-2879: archive/tar: unbounded memory consumption when reading headers + CVE-2022-2880: net/http/httputil: ReverseProxy should not forward unparseable query parameters + CVE-2022-41715: regexp/syntax: limit memory used by parsing regexps . golang-1.18 (1.18.6-1~bpo11+1) bullseye-backports; urgency=medium . * Rebuild for bullseye-backports. . golang-1.18 (1.18.6-1) unstable; urgency=medium . * New upstream version 1.18.6 + CVE-2022-27664: net/http: handle server errors after sending GOAWAY + CVE-2022-32190: net/url: JoinPath does not strip relative path components in all circumstances . golang-1.18 (1.18.5-1~bpo11+1) bullseye-backports; urgency=medium . * Rebuild for bullseye-backports. . golang-1.18 (1.18.5-1) unstable; urgency=medium . * New upstream version 1.18.5 + CVE-2022-32189: math/big: index out of range in Float.GobDecode + cmd/go: Build information embedded by Go 1.18 impairs build reproducibility with cgo flags (Closes: #1008114) * Remove 0005-cmd-compile-revert-fix-missing-dict-pass-for-type-as.patch which has been applied upstream in v1.18.5 * Bump Standards-Version to 4.6.1 (no change) . golang-1.18 (1.18.4-2) unstable; urgency=medium . * Team upload. * cmd/compile: revert "fix missing dict pass for type assertions" Backport patch from https://go.dev/cl/417615 (Closes: #1015088) . golang-1.18 (1.18.4-1~bpo11+1) bullseye-backports; urgency=medium . * Rebuild for bullseye-backports. . golang-1.18 (1.18.4-1) unstable; urgency=medium . * New upstream version 1.18.4 + CVE-2022-1705: net/http: improper sanitization of Transfer-Encoding header + CVE-2022-32148: When httputil.ReverseProxy.ServeHTTP was called with a Request.Header map containing a nil value for the X-Forwarded-For header, ReverseProxy would set the client IP as the value of the X-Forwarded-For header, contrary to its documentation. In the more usual case where a Director function set the X-Forwarded-For header value to nil, ReverseProxy would leave the header unmodified as expected. + CVE-2022-30631: compress/gzip: stack exhaustion in Reader.Read + CVE-2022-30633: encoding/xml: stack exhaustion in Unmarshal + CVE-2022-28131: encoding/xml: stack exhaustion in Decoder.Skip + CVE-2022-30635: encoding/gob: stack exhaustion in Decoder.Decode + CVE-2022-30632: path/filepath: stack exhaustion in Glob + CVE-2022-30630: io/fs: stack exhaustion in Glob + CVE-2022-1962: go/parser: stack exhaustion in all Parse* functions
Branches debian/bullseye-backports
Showing
- VERSION 1 addition, 1 deletionVERSION
- debian/changelog 122 additions, 0 deletionsdebian/changelog
- debian/control 1 addition, 1 deletiondebian/control
- debian/control.in 1 addition, 1 deletiondebian/control.in
- debian/patches/0001-Disable-test-for-UserHomeDir.patch 3 additions, 1 deletiondebian/patches/0001-Disable-test-for-UserHomeDir.patch
- debian/patches/0002-Fix-Lintian-warnings-about-wrong-interpreter-path.patch 17 additions, 2 deletions...2-Fix-Lintian-warnings-about-wrong-interpreter-path.patch
- debian/patches/0003-cmd-dist-increase-default-timeout-scale-for-arm.patch 3 additions, 1 deletion...003-cmd-dist-increase-default-timeout-scale-for-arm.patch
- debian/patches/0004-skip-userns-test-in-schroot-as-well.patch 4 additions, 3 deletions...an/patches/0004-skip-userns-test-in-schroot-as-well.patch
- debian/patches/series 2 additions, 2 deletionsdebian/patches/series
- debian/rules 3 additions, 0 deletionsdebian/rules
- debian/upstream/signing-key.asc 35 additions, 2 deletionsdebian/upstream/signing-key.asc
- misc/cgo/testcarchive/carchive_test.go 149 additions, 93 deletionsmisc/cgo/testcarchive/carchive_test.go
- misc/cgo/testcarchive/testdata/libgo2/libgo2.go 6 additions, 0 deletionsmisc/cgo/testcarchive/testdata/libgo2/libgo2.go
- misc/cgo/testcarchive/testdata/main5.c 9 additions, 4 deletionsmisc/cgo/testcarchive/testdata/main5.c
- misc/cgo/testcshared/cshared_test.go 38 additions, 22 deletionsmisc/cgo/testcshared/cshared_test.go
- src/archive/tar/format.go 4 additions, 0 deletionssrc/archive/tar/format.go
- src/archive/tar/reader.go 12 additions, 2 deletionssrc/archive/tar/reader.go
- src/archive/tar/reader_test.go 10 additions, 1 deletionsrc/archive/tar/reader_test.go
- src/archive/tar/testdata/pax-bad-hdr-large.tar.bz2 0 additions, 0 deletionssrc/archive/tar/testdata/pax-bad-hdr-large.tar.bz2
- src/archive/tar/writer.go 3 additions, 0 deletionssrc/archive/tar/writer.go
Loading
Please register or sign in to comment