[FEDORA-2023-fe53e13b5b] Fedora 38: golang

Severity High
Affected Packages 1
CVEs 3

This update includes a security fix to the net/http package.

Package Affected Version
pkg:rpm/fedora/golang?distro=fedora-38 < 1.20.10.2.fc38
ID
FEDORA-2023-fe53e13b5b
Severity
high
Severity from
CVE-2023-39323
URL
https://bodhi.fedoraproject.org/updates/FEDORA-2023-fe53e13b5b
Published
2023-10-29T01:34:45
(10 months ago)
Modified
2023-10-29T01:34:45
(10 months ago)
Rights
Copyright 2023 Red Hat, Inc.
Other Advisories
Source # ID Name URL
Bugzilla 2243617 Bug #2243617 - [Major Incident] CVE-2023-39325 golang: net/http, x/net/http2: rapid stream resets can cause excessive work (CVE-2023-44487) [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2243617
Bugzilla 2243694 Bug #2243694 - CVE-2023-39323 golang: cmd/go: line directives allows arbitrary execution during build [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2243694
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:rpm/fedora/golang?distro=fedora-38 fedora golang < 1.20.10.2.fc38 fedora-38
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...