Comment 1 for bug 2007220

Revision history for this message
Shengjing Zhu (zhsj) wrote :

golang-1.19 (1.19.6-1) experimental; urgency=medium

  * Team upload
  * New upstream version 1.19.6
    + CVE-2022-41722: path/filepath: path traversal in filepath.Clean on
      Windows
    + CVE-2022-41725: net/http, mime/multipart: denial of service from
      excessive resource consumption
    + CVE-2022-41724: crypto/tls: large handshake records may cause panics
    + CVE-2022-41723: net/http: avoid quadratic complexity in HPACK decoding

 -- Shengjing Zhu <email address hidden> Wed, 15 Feb 2023 10:09:02 +0800

Please sync 1.19.6