Security update for go1.12
This update for go1.12 fixes the following issues:
Security issues fixed:
- CVE-2019-16276: Fixed the handling of invalid HTTP headers, which had allowed request smuggling (bsc#1152082).
- CVE-2019-17596: Fixed a panic in dsa.Verify caused by invalid public keys (bsc#1154402).
Non-security issue fixed:
- Go was updated to version 1.12.12 (bsc#1141689).
This update was imported from the SUSE:SLE-15:Update update project.
- Submitted by Jeff Kowalczyk (jfkw)
Fixed bugs
bnc#1152082
VUL-0: CVE-2019-16276: golang: net/http: invalid headers are normalized, allowing request smuggling
bnc#1141689
go1.12 release tracking
bnc#1154402
VUL-0: CVE-2019-17596: golang: invalid public key causes panic in dsa.Verify