SUSE-SU-2023:2525-1
Dashboard / Vulnerabilities / SUSE-SU-2023:2525-1
SUSE-SU-2023:2525-1
Summary: Security update for go1.19
Details: This update for go1.19 fixes the following issues: Update to go1.19.10 (bsc#1200441): - CVE-2023-29402: cmd/go: Fixed cgo code injection (bsc#1212073). - CVE-2023-29403: runtime: Fixed unexpected behavior of setuid/setgid binaries (bsc#1212074). - CVE-2023-29404: cmd/go: Fixed improper sanitization of LDFLAGS (bsc#1212075). - CVE-2023-29405: cmd/go: Fixed improper sanitization of LDFLAGS (bsc#1212076).
References: https://www.suse.com/support/update/announcement/2023/suse-su-20232525-1/, https://bugzilla.suse.com/1200441, https://bugzilla.suse.com/1212073, https://bugzilla.suse.com/1212074, https://bugzilla.suse.com/1212075, https://bugzilla.suse.com/1212076, https://www.suse.com/security/cve/CVE-2023-29402, https://www.suse.com/security/cve/CVE-2023-29403, https://www.suse.com/security/cve/CVE-2023-29404, https://www.suse.com/security/cve/CVE-2023-29405
Affected packages
Package
Name: go1.19
Purl: pkg:rpm/suse/go1.19&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Development%20Tools%2015%20SP4
Affected ranges
Type: ECOSYSTEM
Events:
