MGASA-2022-0377

Source
https://advisories.mageia.org/MGASA-2022-0377.html
Import Source
https://advisories.mageia.org/MGASA-2022-0377.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2022-0377
Related
Published
2022-10-18T23:14:56Z
Modified
2022-10-18T22:15:07Z
Summary
Updated golang packages fix security vulnerability
Details

regexp/syntax: limit memory used by parsing regexps (CVE-2022-41715) archive/tar: unbounded memory consumption when reading headers (CVE-2022-2879) net/http/httputil: ReverseProxy should not forward unparseable query parameters (CVE-2022-2880)

References
Credits

Affected packages

Mageia:8 / golang

Package

Name
golang
Purl
pkg:rpm/mageia/golang?distro=mageia-8

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.18.7-1.mga8

Ecosystem specific

{
    "section": "core"
}