Advisories ยป MGASA-2021-0537

Updated golang packages fix security vulnerability

Publication date: 03 Dec 2021
Modification date: 03 Dec 2021
Type: security
Affected Mageia releases : 8
CVE: CVE-2021-41771 , CVE-2021-41772

Description

ImportedSymbols in debug/macho (for Open or OpenFat) in Go before 1.16.10
and 1.17.x before 1.17.3 Accesses a Memory Location After the End of a
Buffer, aka an out-of-bounds slice situation. (CVE-2021-41771)
  

Go before 1.16.10 and 1.17.x before 1.17.3 allows an archive/zip
Reader.Open panic via a crafted ZIP archive containing an invalid name or
an empty filename field. (CVE-2021-41772)
                

References

SRPMS

8/core