File _patchinfo of Package patchinfo.25006

<patchinfo incident="25006">
  <issue tracker="bnc" id="1202035">VUL-0: CVE-2022-32189: go1.17,go1.18: encoding/gob and math/big: decoding big.Float and big.Rat can panic</issue>
  <issue tracker="cve" id="2022-32189"/>
  <issue tracker="bnc" id="1201444">VUL-0: CVE-2022-30635: go1.17,go1.18: encoding/gob: stack exhaustion in Decoder.Decode</issue>
  <issue tracker="bnc" id="1201437">VUL-0: CVE-2022-30631: go1.17,go1.18: compress/gzip: stack exhaustion in Reader.Read</issue>
  <issue tracker="bnc" id="1201448">VUL-0: CVE-2022-1962: go1.17,go1.18: go/parser: stack exhaustion in all Parse* functions</issue>
  <issue tracker="bnc" id="1201443">VUL-0: CVE-2022-28131: go1.17,go1.18: encoding/xml: stack exhaustion in Decoder.Skip</issue>
  <issue tracker="bnc" id="1201434">VUL-0: CVE-2022-1705: go1.17,go1.18: net/http: improper sanitization of Transfer-Encoding header</issue>
  <issue tracker="bnc" id="1201447">VUL-0: CVE-2022-30630: go1.17,go1.18: io/fs: stack exhaustion in Glob</issue>
  <issue tracker="bnc" id="1201436">VUL-0: CVE-2022-32148: go1.17,go1.18: net/http/httputil: NewSingleHostReverseProxy - omit X-Forwarded-For not working</issue>
  <issue tracker="bnc" id="1201445">VUL-0: CVE-2022-30632: go1.17,go1.18: path/filepath: stack exhaustion in Glob</issue>
  <issue tracker="bnc" id="1190649">go1.17 release tracking</issue>
  <issue tracker="bnc" id="1201440">VUL-0: CVE-2022-30633: go1.17,go1.18: encoding/xml: stack exhaustion in Unmarshal</issue>
  <issue tracker="cve" id="2022-30631"/>
  <issue tracker="cve" id="2022-1705"/>
  <issue tracker="cve" id="2022-32148"/>
  <issue tracker="cve" id="2022-30632"/>
  <issue tracker="cve" id="2022-28131"/>
  <issue tracker="cve" id="2022-30633"/>
  <issue tracker="cve" id="2022-30630"/>
  <issue tracker="cve" id="2022-30635"/>
  <issue tracker="cve" id="2022-1962"/>
  <packager>jfkw</packager>
  <rating>important</rating>
  <category>security</category>
  <summary>Security update for go1.17</summary>
  <description>This update for go1.17 fixes the following issues:

Update to go version 1.17.13 (bsc#1190649):

- CVE-2022-32189: encoding/gob, math/big: decoding big.Float and big.Rat can panic (bsc#1202035).
- CVE-2022-30635: encoding/gob: stack exhaustion in Decoder.Decode (bsc#1201444).
- CVE-2022-30631: compress/gzip: stack exhaustion in Reader.Read (bsc#1201437).
- CVE-2022-1962: go/parser: stack exhaustion in all Parse* functions (bsc#1201448).
- CVE-2022-28131: encoding/xml: stack exhaustion in Decoder.Skip (bsc#1201443).
- CVE-2022-1705: net/http: improper sanitization of Transfer-Encoding header (bsc#1201434)
- CVE-2022-30630: io/fs: stack exhaustion in Glob (bsc#1201447).
- CVE-2022-32148: net/http/httputil: NewSingleHostReverseProxy - omit X-Forwarded-For not working (bsc#1201436)
- CVE-2022-30632: path/filepath: stack exhaustion in Glob (bsc#1201445).
- CVE-2022-30633: encoding/xml: stack exhaustion in Unmarshal (bsc#1201440).
</description>
</patchinfo>
openSUSE Build Service is sponsored by