SCIENTIFIC-LINUX-ERRATA Archives

April 2018

SCIENTIFIC-LINUX-ERRATA@LISTSERV.FNAL.GOV

Options: Use Monospaced Font
Show Text Part by Default
Show All Mail Headers

Message: [<< First] [< Prev] [Next >] [Last >>]
Topic: [<< First] [< Prev] [Next >] [Last >>]
Author: [<< First] [< Prev] [Next >] [Last >>]

Print Reply
Subject:
From:
Scott Reid <[log in to unmask]>
Reply To:
Date:
Mon, 30 Apr 2018 18:37:12 -0000
Content-Type:
text/plain
Parts/Attachments:
text/plain (34 lines)
Synopsis:          Moderate: golang security, bug fix, and enhancement update
Advisory ID: SLSA-2018:0878-1
Issue Date: 2018-04-10
CVE Numbers: CVE-2017-15042
                   CVE-2017-15041
                   CVE-2018-6574
--

The following packages have been upgraded to a later upstream version:
golang (1.9.4).

Security Fix(es):

* golang: arbitrary code execution during "go get" or "go get -d"
(CVE-2017-15041)

* golang: smtp.PlainAuth susceptible to man-in-the-middle password
harvesting (CVE-2017-15042)

* golang: arbitrary code execution during "go get" via C compiler options
(CVE-2018-6574)

Additional Changes:
--

SL7
  noarch
    golang-docs-1.9.4-1.el7.noarch.rpm
    golang-misc-1.9.4-1.el7.noarch.rpm
    golang-src-1.9.4-1.el7.noarch.rpm
    golang-tests-1.9.4-1.el7.noarch.rpm

- Scientific Linux Development Team

ATOM RSS1 RSS2