File _patchinfo of Package patchinfo.31910
<patchinfo incident="31910">
<issue tracker="bnc" id="1217833">VUL-0: CVE-2023-39326: go1.20,go1.21: net/http: limit chunked data overhead</issue>
<issue tracker="bnc" id="1206346">go1.20 release tracking</issue>
<issue tracker="bnc" id="1217834">VUL-0: CVE-2023-45285: go1.20,go1.21: cmd/go: go get may unexpectedly fallback to insecure git</issue>
<issue tracker="bnc" id="1216943">VUL-0: CVE-2023-45283: go1.20,go1.21: path/filepath: recognize \??\ as a Root Local Device path prefix</issue>
<issue tracker="cve" id="2023-39326"/>
<issue tracker="cve" id="2023-45284"/>
<issue tracker="cve" id="2023-45285"/>
<packager>jfkw</packager>
<rating>important</rating>
<category>security</category>
<summary>Security update for go1.20-openssl</summary>
<description>This update for go1.20-openssl fixes the following issues:
Update to version 1.20.12.1:
- CVE-2023-45285: cmd/go: git VCS qualifier in module path uses git:// scheme (bsc#1217834).
- CVE-2023-45284: path/filepath: Clean removes ending slash for volume on Windows in Go 1.21.4 (bsc#1216943).
- CVE-2023-39326: net/http: limit chunked data overhead (bsc#1217833).
- cmd/compile: internal compiler error: panic during prove while compiling: unexpected induction with too many parents
- cmd/go: TestScript/mod_get_direct fails with "Filename too long" on Windows
</description>
</patchinfo>