[SUSE-SU-2023:3701-1] Security update for go1.21
Severity
Important
Affected Packages
24
CVEs
5
Security update for go1.21
This update for go1.21 fixes the following issues:
Update to go1.21.1 (bsc#1212475).
- CVE-2023-39318: Fixed improper handling of HTML-like comments within script contexts in html/template (bsc#1215084).
- CVE-2023-39319: Fixed improper handling of special tags within script contexts in html/template (bsc#1215085).
- CVE-2023-39320: Fixed arbitrary execution in go.mod toolchain directive (bsc#1215086).
- CVE-2023-39321, CVE-2023-39322: Fixed a panic when processing post-handshake message on QUIC connections in crypto/tls (bsc#1215087).
The following non-security bug was fixed:
- Add missing directory pprof html asset directory to package (bsc#1215090).
- ID
- SUSE-SU-2023:3701-1
- Severity
- important
- URL
- https://www.suse.com/support/update/announcement/2023/suse-su-20233701-1/
- Published
-
2023-09-20T09:19:18
(12 months ago) - Modified
-
2023-09-20T09:19:18
(12 months ago) - Rights
- Copyright 2024 SUSE LLC. All rights reserved.
- Other Advisories
-
- ALAS-2023-1848
- ALAS2-2023-2313
- ALPINE:CVE-2023-39318
- ALPINE:CVE-2023-39319
- ALPINE:CVE-2023-39320
- ALPINE:CVE-2023-39321
- ALPINE:CVE-2023-39322
- ALSA-2023:7762
- ALSA-2023:7763
- ALSA-2023:7764
- ALSA-2023:7765
- ALSA-2023:7766
- ALSA-2024:0121
- ALSA-2024:2160
- ELSA-2023-7762
- ELSA-2023-7763
- ELSA-2023-7764
- ELSA-2023-7765
- ELSA-2023-7766
- ELSA-2024-0121
- ELSA-2024-2988
- FREEBSD:BEB36F39-4D74-11EE-985E-BFF341E78D94
- GLSA-202311-09
- GO-2023-2041
- GO-2023-2042
- GO-2023-2043
- GO-2023-2044
- GO-2023-2045
- openSUSE-SU-2023:0360-1
- RHBA-2023:6364
- RHBA-2023:6928
- RHSA-2023:7762
- RHSA-2023:7763
- RHSA-2023:7764
- RHSA-2023:7765
- RHSA-2023:7766
- RHSA-2024:0121
- RHSA-2024:2160
- RHSA-2024:2988
- SUSE-SU-2023:3700-1
- SUSE-SU-2023:3840-1
- SUSE-SU-2023:4469-1
- USN-6574-1
Type | Package URL | Namespace | Name / Product | Version | Distribution / Platform | Arch | Patch / Fix |
---|---|---|---|---|---|---|---|
Affected | pkg:rpm/suse/go1.21?arch=x86_64&distro=opensuse-leap-15.5 | suse | go1.21 | < 1.21.1-150000.1.6.1 | opensuse-leap-15.5 | x86_64 | |
Affected | pkg:rpm/suse/go1.21?arch=x86_64&distro=opensuse-leap-15.4 | suse | go1.21 | < 1.21.1-150000.1.6.1 | opensuse-leap-15.4 | x86_64 | |
Affected | pkg:rpm/suse/go1.21?arch=s390x&distro=opensuse-leap-15.5 | suse | go1.21 | < 1.21.1-150000.1.6.1 | opensuse-leap-15.5 | s390x | |
Affected | pkg:rpm/suse/go1.21?arch=s390x&distro=opensuse-leap-15.4 | suse | go1.21 | < 1.21.1-150000.1.6.1 | opensuse-leap-15.4 | s390x | |
Affected | pkg:rpm/suse/go1.21?arch=ppc64le&distro=opensuse-leap-15.5 | suse | go1.21 | < 1.21.1-150000.1.6.1 | opensuse-leap-15.5 | ppc64le | |
Affected | pkg:rpm/suse/go1.21?arch=ppc64le&distro=opensuse-leap-15.4 | suse | go1.21 | < 1.21.1-150000.1.6.1 | opensuse-leap-15.4 | ppc64le | |
Affected | pkg:rpm/suse/go1.21?arch=aarch64&distro=opensuse-leap-15.5 | suse | go1.21 | < 1.21.1-150000.1.6.1 | opensuse-leap-15.5 | aarch64 | |
Affected | pkg:rpm/suse/go1.21?arch=aarch64&distro=opensuse-leap-15.4 | suse | go1.21 | < 1.21.1-150000.1.6.1 | opensuse-leap-15.4 | aarch64 | |
Affected | pkg:rpm/suse/go1.21-race?arch=x86_64&distro=opensuse-leap-15.5 | suse | go1.21-race | < 1.21.1-150000.1.6.1 | opensuse-leap-15.5 | x86_64 | |
Affected | pkg:rpm/suse/go1.21-race?arch=x86_64&distro=opensuse-leap-15.4 | suse | go1.21-race | < 1.21.1-150000.1.6.1 | opensuse-leap-15.4 | x86_64 | |
Affected | pkg:rpm/suse/go1.21-race?arch=s390x&distro=opensuse-leap-15.5 | suse | go1.21-race | < 1.21.1-150000.1.6.1 | opensuse-leap-15.5 | s390x | |
Affected | pkg:rpm/suse/go1.21-race?arch=s390x&distro=opensuse-leap-15.4 | suse | go1.21-race | < 1.21.1-150000.1.6.1 | opensuse-leap-15.4 | s390x | |
Affected | pkg:rpm/suse/go1.21-race?arch=ppc64le&distro=opensuse-leap-15.5 | suse | go1.21-race | < 1.21.1-150000.1.6.1 | opensuse-leap-15.5 | ppc64le | |
Affected | pkg:rpm/suse/go1.21-race?arch=ppc64le&distro=opensuse-leap-15.4 | suse | go1.21-race | < 1.21.1-150000.1.6.1 | opensuse-leap-15.4 | ppc64le | |
Affected | pkg:rpm/suse/go1.21-race?arch=aarch64&distro=opensuse-leap-15.5 | suse | go1.21-race | < 1.21.1-150000.1.6.1 | opensuse-leap-15.5 | aarch64 | |
Affected | pkg:rpm/suse/go1.21-race?arch=aarch64&distro=opensuse-leap-15.4 | suse | go1.21-race | < 1.21.1-150000.1.6.1 | opensuse-leap-15.4 | aarch64 | |
Affected | pkg:rpm/suse/go1.21-doc?arch=x86_64&distro=opensuse-leap-15.5 | suse | go1.21-doc | < 1.21.1-150000.1.6.1 | opensuse-leap-15.5 | x86_64 | |
Affected | pkg:rpm/suse/go1.21-doc?arch=x86_64&distro=opensuse-leap-15.4 | suse | go1.21-doc | < 1.21.1-150000.1.6.1 | opensuse-leap-15.4 | x86_64 | |
Affected | pkg:rpm/suse/go1.21-doc?arch=s390x&distro=opensuse-leap-15.5 | suse | go1.21-doc | < 1.21.1-150000.1.6.1 | opensuse-leap-15.5 | s390x | |
Affected | pkg:rpm/suse/go1.21-doc?arch=s390x&distro=opensuse-leap-15.4 | suse | go1.21-doc | < 1.21.1-150000.1.6.1 | opensuse-leap-15.4 | s390x | |
Affected | pkg:rpm/suse/go1.21-doc?arch=ppc64le&distro=opensuse-leap-15.5 | suse | go1.21-doc | < 1.21.1-150000.1.6.1 | opensuse-leap-15.5 | ppc64le | |
Affected | pkg:rpm/suse/go1.21-doc?arch=ppc64le&distro=opensuse-leap-15.4 | suse | go1.21-doc | < 1.21.1-150000.1.6.1 | opensuse-leap-15.4 | ppc64le | |
Affected | pkg:rpm/suse/go1.21-doc?arch=aarch64&distro=opensuse-leap-15.5 | suse | go1.21-doc | < 1.21.1-150000.1.6.1 | opensuse-leap-15.5 | aarch64 | |
Affected | pkg:rpm/suse/go1.21-doc?arch=aarch64&distro=opensuse-leap-15.4 | suse | go1.21-doc | < 1.21.1-150000.1.6.1 | opensuse-leap-15.4 | aarch64 |
# CVE | Description | CVSS | EPSS | EPSS Trend (30 days) | Affected Products | Weaknesses | Security Advisories | Exploits | PoC | Pubblication Date | Modification Date |
---|---|---|---|---|---|---|---|---|---|---|---|
# CVE | Description | CVSS | EPSS | EPSS Trend (30 days) | Affected Products | Weaknesses | Security Advisories | PoC | Pubblication Date | Modification Date |