[FEDORA-2022-59a20edab2] Fedora 37: golang

Severity High
Affected Packages 1
CVEs 3

This release includes security fixes to the archive/tar, net/http/httputil, and
regexp packages, as well as bug fixes to the compiler, the linker, the runtime,
and the go/types package. See the Go 1.19.2 milestone on the issue
tracker for details.

Package Affected Version
pkg:rpm/fedora/golang?distro=fedora-37 <
Source # ID Name URL
Bugzilla 2132879 Bug #2132879 - CVE-2022-2879 golang: archive/tar: unbounded memory consumption when reading headers [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2132879
Bugzilla 2132877 Bug #2132877 - CVE-2022-2880 golang: net/http/httputil: ReverseProxy should not forward unparseable query parameters [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2132877
Bugzilla 2132875 Bug #2132875 - CVE-2022-41715 golang: regexp/syntax: limit memory used by parsing regexps [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2132875
Bugzilla 2114728 Bug #2114728 - golang-1.19.2 is available https://bugzilla.redhat.com/show_bug.cgi?id=2114728
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:rpm/fedora/golang?distro=fedora-37 fedora golang < fedora-37
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date