-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Format: 1.8 Date: Sat, 04 Jun 2022 04:16:02 -0600 Source: golang-1.17 Architecture: source Version: 1.17.11-1~bpo11+1 Distribution: bullseye-backports Urgency: medium Maintainer: Debian Go Compiler Team <team+go-compiler@tracker.debian.org> Changed-By: Anthony Fok <foka@debian.org> Changes: golang-1.17 (1.17.11-1~bpo11+1) bullseye-backports; urgency=medium . * Rebuild for bullseye-backports. . golang-1.17 (1.17.11-1) unstable; urgency=medium . * New upstream version 1.17.11 + CVE-2022-30634: crypto/rand: rand.Read hangs with extremely large buffers (Go issue https://go.dev/issue/52561) + CVE-2022-30629: crypto/tls: session tickets lack random ticket_age_add (Go issue https://go.dev/issue/52814) + CVE-2022-30580: os/exec: empty Cmd.Path can result in running unintended binary on Windows (Go issue https://go.dev/issue/52574) + CVE-2022-29804: path/filepath: Clean(`.\c:`) returns `c:` on Windows (Go issue https://go.dev/issue/52476) Checksums-Sha1: 02cd654559fc37600afc87afc9f4a68acf526948 2903 golang-1.17_1.17.11-1~bpo11+1.dsc 147e9d66ecac763fc045547f6fd8226c5f10c0ee 39732 golang-1.17_1.17.11-1~bpo11+1.debian.tar.xz 5dca3a25ca424834392721a7b046eaf65b1cc054 7114 golang-1.17_1.17.11-1~bpo11+1_amd64.buildinfo Checksums-Sha256: 5d74b67f6677badc50a47bffa4667b2601a8ed7cd68073913d65d2cc51b4c193 2903 golang-1.17_1.17.11-1~bpo11+1.dsc 7747cb5f81a7b9e8a0db0cf06200d1689725f24bf4b252b8d3cb9dc4e04f9e4f 39732 golang-1.17_1.17.11-1~bpo11+1.debian.tar.xz 5776c3435304ac0d03041e8af776ad80d1b8e000247f71098fb6f32d976c9434 7114 golang-1.17_1.17.11-1~bpo11+1_amd64.buildinfo Files: 76201bfbc8e84c9a7b57d0d101df8695 2903 golang optional golang-1.17_1.17.11-1~bpo11+1.dsc a2e9dbb6de489c04886eb893119911bc 39732 golang optional golang-1.17_1.17.11-1~bpo11+1.debian.tar.xz a781dff1316aae3026dfc007f70c0506 7114 golang optional golang-1.17_1.17.11-1~bpo11+1_amd64.buildinfo -----BEGIN PGP SIGNATURE----- iQJEBAEBCAAuFiEEFCQhsZrUqVmW+VBy6iUAtBLFms8FAmKbN20QHGZva2FAZGVi aWFuLm9yZwAKCRDqJQC0EsWaz88jEACbiwVEpfjfqsrrQfemL7lqH2JOUnROslB0 2uik9FQ/DV5jsgKyFl9N/4se8wQbj1yF1uz/kZVSCqzmv9mcEKQeosIAx+0dxbKi z84VNCPs9acI0qQXn3SudjZ9AjEKXLBcTqDrH/dX8ec8+/O7IobQTUUDouusYHcu 1J5MOvglhmMfl6MFiVrNvA1oxd8RehpLbuiykWap1W26e2i8sPpig/DSS59HpJp3 3PYveSNenfN4IzKWgtK7OkdgP1hfFWxR0iMtYfnULw/jJ7Ft/BFunhfQDLqeX9T5 m/SryTS3XnlTTV1sArtQAKB/6PPykquy92qNd2eJ95nwm9FhS+FcVMg8BDyK4aIP 9zH2QQCFEHpAPGcfD5OOm8IQb5ahJ0RQTB5R6RaiBw57iSfxyRdbwU2RAiPq3hc1 Qz06R+JYpwol3f6sgEWIOh5DRZxjuOVdH3s92WY5/V7n88JpZqaUyUePRxnvP0yt 7JNwdcH17CeBgqIUk4/2UgZy8SbLoMN9C4/5Ei6k6eafHlQLLdbcRH7DyZFnZIhF Oeest7LOf1d6iY161Wj8lLY4HJqBXq3LT/JHtOVyocehe0b6qBuhFXMOFPqlU51W vpWE3JSKfC0762vY/f2H2/iLLY34Q93PDal72FBtvlNOxqvMa/xCDbhRqmJr/s8e JF/PE5iWUw== =0fSo -----END PGP SIGNATURE-----