File _patchinfo of Package patchinfo.13059

<patchinfo incident="13059">
  <issue tracker="bnc" id="1152082">VUL-0: CVE-2019-16276: golang: net/http: invalid headers are normalized, allowing request smuggling</issue>
  <issue tracker="bnc" id="1141689">go1.12 release tracking</issue>
  <issue tracker="bnc" id="1154402">VUL-0: CVE-2019-17596: golang: invalid public key causes panic in dsa.Verify</issue>
  <issue tracker="cve" id="2019-17596"/>
  <issue tracker="cve" id="2019-16276"/>
  <packager>jfkw</packager>
  <rating>moderate</rating>
  <category>security</category>
  <summary>Security update for go1.12</summary>
  <description>This update for go1.12 fixes the following issues:

Security issues fixed:

- CVE-2019-16276: Fixed the handling of invalid HTTP headers, which had allowed request smuggling (bsc#1152082).
- CVE-2019-17596: Fixed a panic in dsa.Verify caused by invalid public keys (bsc#1154402).

Non-security issue fixed:

- Go was updated to version 1.12.12 (bsc#1141689).
</description>
</patchinfo>
openSUSE Build Service is sponsored by