Sync golang-1.21 1.21.8-1 (main) from Debian unstable (main)

Bug #2056309 reported by Shengjing Zhu
8
This bug affects 1 person
Affects Status Importance Assigned to Milestone
golang-1.21 (Ubuntu)
Fix Released
Wishlist
Unassigned

Bug Description

Please sync golang-1.21 1.21.8-1 (main) from Debian unstable (main)

Changelog entries since current noble version 1.21.7-2:

golang-1.21 (1.21.8-1) unstable; urgency=medium

  * Team upload
  * New upstream version 1.21.8
    + CVE-2024-24783: crypto/x509: Verify panics on certificates with an
      unknown public key algorithm
    + CVE-2023-45290: net/http: memory exhaustion in Request.ParseMultipartForm
    + CVE-2023-45289: net/http, net/http/cookiejar: incorrect forwarding of
      sensitive headers and cookies on HTTP redirect
    + CVE-2024-24785: html/template: errors returned from MarshalJSON methods
      may break template escaping
    + CVE-2024-24784: net/mail: comments in display names are incorrectly
      handled
  * Update upstream signing key

 -- Shengjing Zhu <email address hidden> Wed, 06 Mar 2024 15:14:10 +0800

Shengjing Zhu (zhsj)
Changed in golang-1.21 (Ubuntu):
importance: Undecided → Wishlist
Revision history for this message
Graham Inggs (ginggs) wrote :

This bug was fixed in the package golang-1.21 - 1.21.8-1
Sponsored for Shengjing Zhu (zhsj)

---------------
golang-1.21 (1.21.8-1) unstable; urgency=medium

  * Team upload
  * New upstream version 1.21.8
    + CVE-2024-24783: crypto/x509: Verify panics on certificates with an
      unknown public key algorithm
    + CVE-2023-45290: net/http: memory exhaustion in Request.ParseMultipartForm
    + CVE-2023-45289: net/http, net/http/cookiejar: incorrect forwarding of
      sensitive headers and cookies on HTTP redirect
    + CVE-2024-24785: html/template: errors returned from MarshalJSON methods
      may break template escaping
    + CVE-2024-24784: net/mail: comments in display names are incorrectly
      handled
  * Update upstream signing key

 -- Shengjing Zhu <email address hidden> Wed, 06 Mar 2024 15:14:10 +0800

Changed in golang-1.21 (Ubuntu):
status: New → Fix Released
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.