[Bug 2034690] [NEW] Sync golang-1.21 1.21.1-1 (main) from Debian unstable (main)

Launchpad Bug Tracker 2034690 at bugs.launchpad.net
Thu Sep 7 10:47:35 UTC 2023


You have been subscribed to a public bug by Shengjing Zhu (zhsj):

Please sync golang-1.21 1.21.1-1 (main) from Debian unstable (main)

Changelog entries since current mantic version 1.21.0-1:

golang-1.21 (1.21.1-1) unstable; urgency=medium

  * Team upload
  * New upstream version 1.21.1
    + CVE-2023-39320: cmd/go: go.mod toolchain directive allows arbitrary
      execution
    + CVE-2023-39318: html/template: improper handling of HTML-like comments
      within script contexts
    + CVE-2023-39319: html/template: improper handling of special tags within
      script contexts
    + CVE-2023-39321/CVE-2023-39322: crypto/tls: panic when processing
      post-handshake message on QUIC connections

 -- Shengjing Zhu <zhsj at debian.org>  Thu, 07 Sep 2023 11:51:55 +0800

** Affects: golang-1.21 (Ubuntu)
     Importance: Wishlist
         Status: New

-- 
Sync golang-1.21 1.21.1-1 (main) from Debian unstable (main)
https://bugs.launchpad.net/bugs/2034690
You received this bug notification because you are a member of Ubuntu Sponsors, which is subscribed to the bug report.



More information about the Ubuntu-sponsors mailing list