Information on source package golang-1.7

Available versions

ReleaseVersion
stretch1.7.4-2+deb9u1
stretch (security)1.7.4-2+deb9u3

Open issues

BugstretchDescription
CVE-2021-39293vulnerable
CVE-2021-36221vulnerableGo before 1.15.15 and 1.16.x before 1.16.7 has a race condition that c ...
CVE-2021-34558vulnerable (no DSA, postponed)The crypto/tls package of Go through 1.16.5 does not properly assert t ...
CVE-2021-33197vulnerable (no DSA, postponed)In Go before 1.15.13 and 1.16.x before 1.16.5, some configurations of ...
CVE-2021-33196vulnerable (no DSA, postponed)In archive/zip in Go before 1.15.13 and 1.16.x before 1.16.5, a crafte ...
CVE-2021-33195vulnerable (no DSA, postponed)Go before 1.15.13 and 1.16.x before 1.16.5 has functions for DNS looku ...
CVE-2021-31525vulnerable (no DSA, postponed)net/http in Go before 1.15.12 and 1.16.x before 1.16.4 allows remote a ...
CVE-2021-29923vulnerableGo before 1.17 does not properly consider extraneous zero characters a ...
CVE-2021-27918vulnerable (no DSA, postponed)encoding/xml in Go before 1.15.9 and 1.16.x before 1.16.1 has an infin ...
CVE-2021-3115vulnerable (no DSA, ignored)Go before 1.14.14 and 1.15.x before 1.15.7 on Windows is vulnerable to ...
CVE-2020-29511vulnerable (no DSA, ignored)The encoding/xml package in Go (all versions) does not correctly prese ...
CVE-2020-29510vulnerable (no DSA, ignored)The encoding/xml package in Go versions 1.15 and earlier does not corr ...
CVE-2020-28367vulnerable (no DSA, ignored)Go before 1.14.12 and 1.15.x before 1.15.5 allows Argument Injection. ...
CVE-2020-28366vulnerable (no DSA, ignored)Go before 1.14.12 and 1.15.x before 1.15.5 allows Code Injection. ...
CVE-2020-24553vulnerable (no DSA)Go before 1.14.8 and 1.15.x before 1.15.1 allows XSS because text/html ...
CVE-2019-14809vulnerable (no DSA, ignored)net/url in Go before 1.11.13 and 1.12.x before 1.12.8 mishandles malfo ...
CVE-2019-9514vulnerable (no DSA, ignored)Some HTTP/2 implementations are vulnerable to a reset flood, potential ...
CVE-2019-9512vulnerable (no DSA, ignored)Some HTTP/2 implementations are vulnerable to ping floods, potentially ...
CVE-2018-16875vulnerable (no DSA, ignored)The crypto/x509 package of Go before 1.10.6 and 1.11.x before 1.11.3 d ...
CVE-2018-6574vulnerable (no DSA, ignored)Go before 1.8.7, Go 1.9.x before 1.9.4, and Go 1.10 pre-releases befor ...
CVE-2017-15042vulnerable (no DSA, ignored)An unintended cleartext issue exists in Go before 1.8.4 and 1.9.x befo ...
CVE-2017-8932vulnerable (no DSA, ignored)A bug in the standard library ScalarMult implementation of curve P-256 ...

Open unimportant issues

BugstretchDescription
CVE-2020-29509vulnerableThe encoding/xml package in Go (all versions) does not correctly prese ...

Resolved issues

BugDescription
CVE-2021-33198In Go before 1.15.13 and 1.16.x before 1.16.5, there can be a panic fo ...
CVE-2021-3114In Go before 1.14.14 and 1.15.x before 1.15.7, crypto/elliptic/p224.go ...
CVE-2020-28362Go before 1.14.12 and 1.15.x before 1.15.4 allows Denial of Service. ...
CVE-2020-16845Go before 1.13.15 and 14.x before 1.14.7 can have an infinite read loo ...
CVE-2020-15586Go before 1.13.13 and 1.14.x before 1.14.5 has a data race in some net ...
CVE-2020-7919Go before 1.12.16 and 1.13.x before 1.13.7 (and the crypto/cryptobyte ...
CVE-2019-17596Go before 1.12.11 and 1.3.x before 1.13.2 can panic upon an attempt to ...
CVE-2019-16276Go before 1.12.10 and 1.13.x before 1.13.1 allow HTTP Request Smugglin ...
CVE-2019-9741An issue was discovered in net/http in Go 1.11.5. CRLF injection is po ...
CVE-2019-6486Go before 1.10.8 and 1.11.x before 1.11.5 mishandles P-521 and P-384 e ...
CVE-2018-16874In Go before 1.10.6 and 1.11.x before 1.11.3, the "go get" command is ...
CVE-2018-16873In Go before 1.10.6 and 1.11.x before 1.11.3, the "go get" command is ...
CVE-2018-7187The "go get" implementation in Go 1.9.4, when the -insecure command-li ...
CVE-2017-1000098The net/http package's Request.ParseMultipartForm method starts writin ...
CVE-2017-1000097On Darwin, user's trust preferences for root certificates were not hon ...
CVE-2017-15041Go before 1.8.4 and 1.9.x before 1.9.1 allows "go get" remote command ...

Security announcements

DSA / DLADescription
DLA-2591-1golang-1.7 - security update
DLA-2459-1golang-1.7 - security update
DSA-4379-1golang-1.7 - security update

Search for package or bug name: Reporting problems