File _patchinfo of Package patchinfo.20199
<patchinfo incident="20199">
<issue tracker="cve" id="2021-33198"/>
<issue tracker="cve" id="2021-33196"/>
<issue tracker="cve" id="2021-33195"/>
<issue tracker="cve" id="2021-33197"/>
<issue tracker="bnc" id="1187444">VUL-0: CVE-2021-33197: go1.16,go1.15: go: net/http/httputil: ReverseProxy forwards Connection headers if first one is empty</issue>
<issue tracker="bnc" id="1187445">VUL-0: CVE-2021-33198: go1.16,go1.15: go: math/big.Rat SetString and UnmarshalText panic with very large exponents</issue>
<issue tracker="bnc" id="1186622">VUL-0: CVE-2021-33196: go1.14,go1.15,go1.16: Malformed archive may cause panic or memory exhaustion</issue>
<issue tracker="bnc" id="1182345">go1.16 release tracking</issue>
<issue tracker="bnc" id="1187443">VUL-0: CVE-2021-33195: go1.16,go1.15: go: net: Lookup functions may return invalid host names</issue>
<packager>jfkw</packager>
<rating>important</rating>
<category>security</category>
<summary>Security update for go1.16</summary>
<description>This update for go1.16 fixes the following issues:
Update to 1.16.5.
Includes these security fixes
- CVE-2021-33195: net: Lookup functions may return invalid host names (bsc#1187443).
- CVE-2021-33196: archive/zip: malformed archive may cause panic or memory exhaustion (bsc#1186622).
- CVE-2021-33197: net/http/httputil: ReverseProxy forwards Connection headers if first one is empty (bsc#1187444)
- CVE-2021-33198: math/big: (*Rat).SetString with "1.770p02041010010011001001" crashes with "makeslice: len out of range" (bsc#1187445).
</description>
</patchinfo>