File _patchinfo of Package patchinfo.28231
<patchinfo incident="28231">
<issue tracker="bnc" id="1208271">VUL-0: TRACKERBUG: CVE-2022-41724: go1.19,go1.20: crypto/tls: large handshake records may cause panics</issue>
<issue tracker="bnc" id="1200441">go1.19 release tracking</issue>
<issue tracker="bnc" id="1208270">VUL-0: TRACKERBUG: CVE-2022-41723: go1.19,go1.20: net/http: avoid quadratic complexity in HPACK decoding</issue>
<issue tracker="bnc" id="1208272">VUL-0: TRACKERBUG: CVE-2022-41725: go1.19,go1.20: net/http, mime/multipart: denial of service from excessive resource consumption</issue>
<issue tracker="bnc" id="1209030">VUL-0: CVE-2023-24532: go1.19,go1.20: crypto/elliptic: incorrect P-256 ScalarMult and ScalarBaseMult results</issue>
<issue tracker="cve" id="2022-41723"/>
<issue tracker="cve" id="2022-41724"/>
<issue tracker="cve" id="2023-24532"/>
<issue tracker="cve" id="2022-41725"/>
<issue tracker="cve" id="2022-41720"/>
<issue tracker="bnc" id="1206134">VUL-0: CVE-2022-41720: go1.18,go1.19: os, net/http: avoid escapes from os.DirFS and http.Dir on Windows</issue>
<category>security</category>
<rating>important</rating>
<packager>msmeissn</packager>
<summary>Security update for container-suseconnect</summary>
<description>
This update of container-suseconnect fixes the following issue:
- container-suseconnect was rebuilt against the current go1.19 release, fixing security issues and other bugs fixed in go1.19.7.
- CVE-2022-41723: Fixed quadratic complexity in HPACK decoding (bsc#1208270).
- CVE-2022-41724: Fixed panic with arge handshake records in crypto/tls (bsc#1208271).
- CVE-2022-41725: Fixed denial of service from excessive resource consumption in net/http and mime/multipart (bsc#1208272).
- CVE-2023-24532: Fixed incorrect P-256 ScalarMult and ScalarBaseMult results (bsc#1209030).
- CVE-2022-41720: os, net/http: avoid escapes from os.DirFS and http.Dir on Windows (bsc#1206134).
</description>
</patchinfo>