MGASA-2021-0537
Dashboard / Vulnerabilities / MGASA-2021-0537
MGASA-2021-0537
Summary: Updated golang packages fix security vulnerability
Details: ImportedSymbols in debug/macho (for Open or OpenFat) in Go before 1.16.10 and 1.17.x before 1.17.3 Accesses a Memory Location After the End of a Buffer, aka an out-of-bounds slice situation. (CVE-2021-41771) Go before 1.16.10 and 1.17.x before 1.17.3 allows an archive/zip Reader.Open panic via a crafted ZIP archive containing an invalid name or an empty filename field. (CVE-2021-41772)
References: https://advisories.mageia.org/MGASA-2021-0537.html, https://bugs.mageia.org/show_bug.cgi?id=29717, https://lists.suse.com/pipermail/sle-security-updates/2021-December/009791.html, https://lists.opensuse.org/archives/list/[email protected]/thread/DRORBGLIRSYNYTIE3EARJHAXYB2X5YQ3/
Affected packages
Package
Name: golang
Purl: pkg:rpm/mageia/golang?arch=source&distro=mageia-8
Affected ranges
Type: ECOSYSTEM
Events:
