-------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2022-59a20edab2 2022-10-17 22:54:25.295501 --------------------------------------------------------------------------------
Name : golang Product : Fedora 37 Version : 1.19.2 Release : 1.fc37 URL : https://go.dev Summary : The Go Programming Language Description : The Go Programming Language.
-------------------------------------------------------------------------------- Update Information:
This release includes security fixes to the archive/tar, net/http/httputil, and regexp packages, as well as bug fixes to the compiler, the linker, the runtime, and the go/types package. See the [Go 1.19.2 milestone](https://github.com/golan g/go/issues?q=milestone%3AGo1.19.2+label%3ACherryPickApproved) on the issue tracker for details. -------------------------------------------------------------------------------- ChangeLog:
* Tue Oct 4 2022 Alejandro S��ez asm@redhat.com - 1.19.2-1 - Update to go1.19.2 -------------------------------------------------------------------------------- References:
[ 1 ] Bug #2114728 - golang-1.19.2 is available https://bugzilla.redhat.com/show_bug.cgi?id=2114728 [ 2 ] Bug #2132875 - CVE-2022-41715 golang: regexp/syntax: limit memory used by parsing regexps [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2132875 [ 3 ] Bug #2132877 - CVE-2022-2880 golang: net/http/httputil: ReverseProxy should not forward unparseable query parameters [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2132877 [ 4 ] Bug #2132879 - CVE-2022-2879 golang: archive/tar: unbounded memory consumption when reading headers [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2132879 --------------------------------------------------------------------------------
This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2022-59a20edab2' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label
All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys --------------------------------------------------------------------------------
package-announce@lists.fedoraproject.org