[ALAS-2023-1871] Amazon Linux AMI 2014.03 - ALAS-2023-1871: important priority package update for golang

Severity Important
Affected Packages 10
CVEs 3

Package updates are available for Amazon Linux AMI that fix the following vulnerabilities:
CVE-2023-44487:
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.

CVE-2023-39325:
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.

CVE-2023-39323:
Line directives ("//line") can be used to bypass the restrictions on "//go:cgo_" directives, allowing blocked linker and compiler flags to be passed during compilation. This can result in unexpected execution of arbitrary code when running "go build". The line directive requires the absolute path of the file in which the directive lives, which makes exploiting this issue significantly more complex.

ID
ALAS-2023-1871
Severity
important
URL
https://alas.aws.amazon.com/ALAS-2023-1871.html
Published
2023-10-16T13:45:00
(11 months ago)
Modified
2023-10-18T20:09:00
(11 months ago)
Rights
Amazon Linux Security Team
Other Advisories
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:rpm/amazonlinux/golang?arch=x86_64&distro=amazonlinux-1 amazonlinux golang < 1.20.10-1.48.amzn1 amazonlinux-1 x86_64
Affected pkg:rpm/amazonlinux/golang?arch=i686&distro=amazonlinux-1 amazonlinux golang < 1.20.10-1.48.amzn1 amazonlinux-1 i686
Affected pkg:rpm/amazonlinux/golang-tests?arch=noarch&distro=amazonlinux-1 amazonlinux golang-tests < 1.20.10-1.48.amzn1 amazonlinux-1 noarch
Affected pkg:rpm/amazonlinux/golang-src?arch=noarch&distro=amazonlinux-1 amazonlinux golang-src < 1.20.10-1.48.amzn1 amazonlinux-1 noarch
Affected pkg:rpm/amazonlinux/golang-shared?arch=x86_64&distro=amazonlinux-1 amazonlinux golang-shared < 1.20.10-1.48.amzn1 amazonlinux-1 x86_64
Affected pkg:rpm/amazonlinux/golang-shared?arch=i686&distro=amazonlinux-1 amazonlinux golang-shared < 1.20.10-1.48.amzn1 amazonlinux-1 i686
Affected pkg:rpm/amazonlinux/golang-misc?arch=noarch&distro=amazonlinux-1 amazonlinux golang-misc < 1.20.10-1.48.amzn1 amazonlinux-1 noarch
Affected pkg:rpm/amazonlinux/golang-docs?arch=noarch&distro=amazonlinux-1 amazonlinux golang-docs < 1.20.10-1.48.amzn1 amazonlinux-1 noarch
Affected pkg:rpm/amazonlinux/golang-bin?arch=x86_64&distro=amazonlinux-1 amazonlinux golang-bin < 1.20.10-1.48.amzn1 amazonlinux-1 x86_64
Affected pkg:rpm/amazonlinux/golang-bin?arch=i686&distro=amazonlinux-1 amazonlinux golang-bin < 1.20.10-1.48.amzn1 amazonlinux-1 i686
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...