Information on source package golang-1.18

Available versions

ReleaseVersion
bookworm1.18.8-1
sid1.18.8-1

Resolved issues

BugDescription
CVE-2022-41716Due to unsanitized NUL values, attackers may be able to maliciously se ...
CVE-2022-41715Programs which compile regular expressions from untrusted sources may ...
CVE-2022-32190JoinPath and URL.JoinPath do not remove ../ path elements appended to ...
CVE-2022-32189A too-short encoded message can cause a panic in Float.GobDecode and R ...
CVE-2022-32148Improper exposure of client IP addresses in net/http before Go 1.17.12 ...
CVE-2022-30635Uncontrolled recursion in Decoder.Decode in encoding/gob before Go 1.1 ...
CVE-2022-30634Infinite loop in Read in crypto/rand before Go 1.17.11 and Go 1.18.3 o ...
CVE-2022-30633Uncontrolled recursion in Unmarshal in encoding/xml before Go 1.17.12 ...
CVE-2022-30632Uncontrolled recursion in Glob in path/filepath before Go 1.17.12 and ...
CVE-2022-30631Uncontrolled recursion in Reader.Read in compress/gzip before Go 1.17. ...
CVE-2022-30630Uncontrolled recursion in Glob in io/fs before Go 1.17.12 and Go 1.18. ...
CVE-2022-30629Non-random values for ticket_age_add in session tickets in crypto/tls ...
CVE-2022-30580Code injection in Cmd.Start in os/exec before Go 1.17.11 and Go 1.18.3 ...
CVE-2022-29804In filepath.Clean in path/filepath in Go before 1.17.11 and 1.18.x bef ...
CVE-2022-29526Go before 1.17.10 and 1.18.x before 1.18.2 has Incorrect Privilege Ass ...
CVE-2022-28327The generic P-256 feature in crypto/elliptic in Go before 1.17.9 and 1 ...
CVE-2022-28131In Decoder.Skip in encoding/xml in Go before 1.17.12 and 1.18.x before ...
CVE-2022-27664In net/http in Go before 1.18.6 and 1.19.x before 1.19.1, attackers ca ...
CVE-2022-27536Certificate.Verify in crypto/x509 in Go 1.18.x before 1.18.1 can be ca ...
CVE-2022-24921regexp.Compile in Go before 1.16.15 and 1.17.x before 1.17.8 allows st ...
CVE-2022-24675encoding/pem in Go before 1.17.9 and 1.18.x before 1.18.1 has a Decode ...
CVE-2022-23806Curve.IsOnCurve in crypto/elliptic in Go before 1.16.14 and 1.17.x bef ...
CVE-2022-23773cmd/go in Go before 1.16.14 and 1.17.x before 1.17.7 can misinterpret ...
CVE-2022-23772Rat.SetString in math/big in Go before 1.16.14 and 1.17.x before 1.17. ...
CVE-2022-2880Requests forwarded by ReverseProxy include the raw query parameters fr ...
CVE-2022-2879Reader.Read does not set a limit on the maximum size of file headers. ...
CVE-2022-1962Uncontrolled recursion in the Parse functions in go/parser before Go 1 ...
CVE-2022-1705Acceptance of some invalid Transfer-Encoding headers in the HTTP/1 cli ...

Search for package or bug name: Reporting problems