The Go Programming Language.\r\n\r\n Security Fix(es):\r\n\r\n The encoding/xml package in Go (all versions) does not correctly preserve the semantics of attribute namespace prefixes during tokenization round-trips, which allows an attacker to craft inputs that behave in conflicting ways during different stages of processing in affected downstream applications.(CVE-2020-29509)\r\n\r\n
{
"severity": "Medium"
}{
"noarch": [
"golang-help-1.13.15-2.oe1.noarch.rpm",
"golang-devel-1.13.15-2.oe1.noarch.rpm",
"golang-help-1.13.15-2.oe1.noarch.rpm",
"golang-devel-1.13.15-2.oe1.noarch.rpm"
],
"aarch64": [
"golang-1.13.15-2.oe1.aarch64.rpm",
"golang-1.13.15-2.oe1.aarch64.rpm"
],
"x86_64": [
"golang-1.13.15-2.oe1.x86_64.rpm",
"golang-1.13.15-2.oe1.x86_64.rpm"
],
"src": [
"golang-1.13.15-2.oe1.src.rpm",
"golang-1.13.15-2.oe1.src.rpm"
]
}