-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Format: 1.8 Date: Mon, 25 Jan 2021 03:15:38 +0800 Source: golang-1.11 Architecture: source Version: 1.11.6-1+deb10u4 Distribution: buster-security Urgency: high Maintainer: Go Compiler Team <team+go-compiler@tracker.debian.org> Changed-By: Shengjing Zhu <zhsj@debian.org> Changes: golang-1.11 (1.11.6-1+deb10u4) buster-security; urgency=high . * Team upload. . [ Dr. Tobias Quathamer ] * cryptobyte: fix panic due to malformed ASN.1 inputs on 32-bit archs https://github.com/golang/go/issues/36837 CVE-2020-7919 * net/http: Expect 100-continue panics in httputil.ReverseProxy https://github.com/golang/go/issues/34902 CVE-2020-15586 * encoding/binary: ReadUvarint and ReadVarint can read an unlimited number of bytes from invalid inputs https://github.com/golang/go/issues/40618 CVE-2020-16845 . [ Shengjing Zhu ] * crypto/elliptic: incorrect operations on the P-224 curve https://github.com/golang/go/issues/43786 CVE-2021-3114 Checksums-Sha1: dd1c7a8a36bd9bdbf15c01134299a24cdf12a64d 2034 golang-1.11_1.11.6-1+deb10u4.dsc 15daf96aa6de7cd9c0b5ad817b50d721871c7355 41716 golang-1.11_1.11.6-1+deb10u4.debian.tar.xz 6f7a2f6a88b5b3683cb990164be081d6696672e3 6007 golang-1.11_1.11.6-1+deb10u4_amd64.buildinfo Checksums-Sha256: e928d03ff19234a4649944069c53b950512c537fbb676bb8ad4850e0ca7b7479 2034 golang-1.11_1.11.6-1+deb10u4.dsc 7e36379053403f4c53eec047bbd9d275ebf05000afad80c5b9c3e6973d0277d7 41716 golang-1.11_1.11.6-1+deb10u4.debian.tar.xz e1a7e5bac9151dccc7dd5b8d03f4078567fab1bfdaf68b36f8616b27cfb7701d 6007 golang-1.11_1.11.6-1+deb10u4_amd64.buildinfo Files: e9ee0317545c14a242e44b9060975c18 2034 devel optional golang-1.11_1.11.6-1+deb10u4.dsc dddb5b98d779f2ead1bc1e2b673f5f4d 41716 devel optional golang-1.11_1.11.6-1+deb10u4.debian.tar.xz dcdb6ead54e5f533dceaf6bf128e0c18 6007 devel optional golang-1.11_1.11.6-1+deb10u4_amd64.buildinfo -----BEGIN PGP SIGNATURE----- iIYEARYIAC4WIQTiXc95jUQrjt9HgU3EhUo4GOCwFgUCYA3Q/RAcemhzakBkZWJp YW4ub3JnAAoJEMSFSjgY4LAWA6cBAK6w2qKVbdElQIYa6WSFJegXPcXMkXyd8TMe NeZlhB9GAQDwDw1qR0ncQISffp4El95NkbAagL89GiupN+4X/AbzCg== =L5n/ -----END PGP SIGNATURE-----