Advisories ยป MGASA-2022-0377

Updated golang packages fix security vulnerability

Publication date: 18 Oct 2022
Modification date: 18 Oct 2022
Type: security
Affected Mageia releases : 8
CVE: CVE-2022-2879 , CVE-2022-2889 , CVE-2022-41715

Description

regexp/syntax: limit memory used by parsing regexps (CVE-2022-41715)
archive/tar: unbounded memory consumption when reading headers
(CVE-2022-2879)
net/http/httputil: ReverseProxy should not forward unparseable query
parameters (CVE-2022-2880)
                

References

SRPMS

8/core