FS#70320 - [golang-golang-x-text] [Security] denial of service (CVE-2020-28852 CVE-2020-28851)
Attached to Project:
Community Packages
Opened by Jonas Witschel (diabonas) - Tuesday, 06 April 2021, 19:14 GMT
Last edited by Jelle van der Waa (jelly) - Sunday, 24 September 2023, 10:42 GMT
Opened by Jonas Witschel (diabonas) - Tuesday, 06 April 2021, 19:14 GMT
Last edited by Jelle van der Waa (jelly) - Sunday, 24 September 2023, 10:42 GMT
|
Details
Summary
======= The package golang-golang-x-text is vulnerable to denial of service via CVE-2020-28852 and CVE-2020-28851. Guidance ======== Upgrading to the latest version 0.3.6 (https://github.com/golang/text/releases/tag/v0.3.6) fixes the issues. References ========== https://security.archlinux.org/AVG-1396 https://github.com/golang/go/issues/42536 https://play.golang.org/p/SwAU9tKYRsj https://github.com/golang/text/commit/4482a914f52311356f6f4b7a695d4075ca22c0c6 https://github.com/golang/go/issues/42535 https://play.golang.org/p/FCHj_rCBdiH https://github.com/golang/text/commit/e3aa4adf54f644ca0cb35f1f1fb19b239c40ef04 |
This task depends upon
Closed by Jelle van der Waa (jelly)
Sunday, 24 September 2023, 10:42 GMT
Reason for closing: Deferred
Additional comments about closing: Dropped from repos
Sunday, 24 September 2023, 10:42 GMT
Reason for closing: Deferred
Additional comments about closing: Dropped from repos
Comment by
Buggy McBugFace (bugbot) - Tuesday,
08 August 2023, 19:11 GMT
This is an automated comment as this bug is open for more then 2
years. Please reply if you still experience this bug otherwise
this issue will be closed after 1 month.