File _patchinfo of Package patchinfo.20199

<patchinfo incident="20199">
  <issue tracker="cve" id="2021-33198"/>
  <issue tracker="cve" id="2021-33196"/>
  <issue tracker="cve" id="2021-33195"/>
  <issue tracker="cve" id="2021-33197"/>
  <issue tracker="bnc" id="1187444">VUL-0: CVE-2021-33197: go1.16,go1.15: go: net/http/httputil: ReverseProxy forwards Connection headers if first one is empty</issue>
  <issue tracker="bnc" id="1187445">VUL-0: CVE-2021-33198: go1.16,go1.15: go: math/big.Rat SetString and UnmarshalText panic with very large exponents</issue>
  <issue tracker="bnc" id="1186622">VUL-0: CVE-2021-33196: go1.14,go1.15,go1.16: Malformed archive may cause panic or memory exhaustion</issue>
  <issue tracker="bnc" id="1182345">go1.16 release tracking</issue>
  <issue tracker="bnc" id="1187443">VUL-0: CVE-2021-33195: go1.16,go1.15: go: net: Lookup functions may return invalid host names</issue>
  <packager>jfkw</packager>
  <rating>important</rating>
  <category>security</category>
  <summary>Security update for go1.16</summary>
  <description>This update for go1.16 fixes the following issues:

Update to 1.16.5.

Includes these security fixes 

- CVE-2021-33195: net: Lookup functions may return invalid host names (bsc#1187443).
- CVE-2021-33196: archive/zip: malformed archive may cause panic or memory exhaustion (bsc#1186622).
- CVE-2021-33197: net/http/httputil: ReverseProxy forwards Connection headers if first one is empty (bsc#1187444)
- CVE-2021-33198: math/big: (*Rat).SetString with "1.770p02041010010011001001" crashes with "makeslice: len out of range" (bsc#1187445).
</description>
</patchinfo>
openSUSE Build Service is sponsored by