SUSE-SU-2023:2127-1
Dashboard / Vulnerabilities / SUSE-SU-2023:2127-1
SUSE-SU-2023:2127-1
Summary: Security update for go1.19
Details: This update for go1.19 fixes the following issues: Update to 1.19.9 (bnc#1200441): - CVE-2023-24539: fixed an improper sanitization of CSS values (bnc#1211029). - CVE-2023-24540: fixed an improper handling of JavaScript whitespace (bnc#1211030). - CVE-2023-29400: fixed an improper handling of empty HTML attributes (bnc#1211031). - runtime: automatically bump RLIMIT_NOFILE on Unix - cmd/compile: inlining function that references function literals generates bad code. - cmd/compile: encoding/binary.PutUint16 sometimes doesn't write. - crypto/tls: TLSv1.3 connection fails with invalid PSK binder. - cmd/compile: incorrect inline function variable. Non-security fixes: - Various packaging fixes (boo#1210963, boo#1210938, boo#1211073) - Reduced install size (jsc#PED-1962).
References: https://www.suse.com/support/update/announcement/2023/suse-su-20232127-1/, https://bugzilla.suse.com/1200441, https://bugzilla.suse.com/1210127, https://bugzilla.suse.com/1210128, https://bugzilla.suse.com/1210129, https://bugzilla.suse.com/1210130, https://bugzilla.suse.com/1210938, https://bugzilla.suse.com/1210963, https://bugzilla.suse.com/1211029, https://bugzilla.suse.com/1211030, https://bugzilla.suse.com/1211031, https://bugzilla.suse.com/1211073, https://www.suse.com/security/cve/CVE-2023-24534, https://www.suse.com/security/cve/CVE-2023-24536, https://www.suse.com/security/cve/CVE-2023-24537, https://www.suse.com/security/cve/CVE-2023-24538, https://www.suse.com/security/cve/CVE-2023-24539, https://www.suse.com/security/cve/CVE-2023-24540, https://www.suse.com/security/cve/CVE-2023-29400
Affected packages
Package
Name: go1.19
Purl: pkg:rpm/suse/go1.19&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Development%20Tools%2015%20SP4
Affected ranges
Type: ECOSYSTEM
Events:
