-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Tue, 06 Dec 2022 13:39:48 -0600 Source: golang-1.18 Built-For-Profiles: noudeb Architecture: source Version: 1.18.9-1 Distribution: unstable Urgency: medium Maintainer: Debian Go Compiler Team <team+go-compiler@tracker.debian.org> Changed-By: William 'jawn-smith' Wilson <jawn-smith@ubuntu.com> Changes: golang-1.18 (1.18.9-1) unstable; urgency=medium . * New upstream version 1.18.9 + CVE-2022-41720: os, net/http: avoid escapes from os.DirFS and http.Dir on Windows + CVE-2022-41717: net/http: limit canonical header cache by bytes, not entries Checksums-Sha1: ea0e22bf072f857176ad517aba996da0a9f46e0e 2836 golang-1.18_1.18.9-1.dsc 21ba2d3166a81e1b60d92e262cfb950980b6a9a0 22878625 golang-1.18_1.18.9.orig.tar.gz bc092ced4846a61f5653653c4224c64feb3476c2 819 golang-1.18_1.18.9.orig.tar.gz.asc 5be2471b8df249677aaf8633fa0fbbde64ec621c 42184 golang-1.18_1.18.9-1.debian.tar.xz fb5b3f14bf3cee129841d00eb7cd47d6ac4ecd29 7460 golang-1.18_1.18.9-1_source.buildinfo Checksums-Sha256: a7105312338ec7455d45bd0c1757474a4b6c0b2043f0bab7a8987478cd5cbe5f 2836 golang-1.18_1.18.9-1.dsc fbe7f09b96aca3db6faeaf180da8bb632868ec049731e355ff61695197c0e3ea 22878625 golang-1.18_1.18.9.orig.tar.gz 88a3de1ff3bbad5ea3d57eac66e80c849c32104abb773bc20ed3e6150420cb58 819 golang-1.18_1.18.9.orig.tar.gz.asc 2fabeb46aeb7b9601f1a36bed625c78021ec4c6d6d63fbd0b5edcf5fb960b565 42184 golang-1.18_1.18.9-1.debian.tar.xz 3af6a3748aad29fd020e4f6a3be2733a42fa75514fb2964fa46435e2468bf603 7460 golang-1.18_1.18.9-1_source.buildinfo Files: 008ef60845e065befc5fe1e07596eea7 2836 golang optional golang-1.18_1.18.9-1.dsc e2caa7c4de49aa77a14c694bfc9a5cd1 22878625 golang optional golang-1.18_1.18.9.orig.tar.gz b8ddacc89f1fd9da4cb8f21f6610ee4c 819 golang optional golang-1.18_1.18.9.orig.tar.gz.asc 329215292a895f772ae26e10e9179875 42184 golang optional golang-1.18_1.18.9-1.debian.tar.xz f6b75ab8bee56b5464f32ea4b0a466b1 7460 golang optional golang-1.18_1.18.9-1_source.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEfm2fYq1zA4h6PB3QSRbXqx16OAQFAmOR9wQACgkQSRbXqx16 OATOrw/9HpGFohMoxqWTB/sN57NlrO2etDY8mMW/RGUFGe3H9v0dx5B71sT4sC3C DAwIhcclipoc9yUi0PNg1+cbUy4XL3CGO7WqqyUdhaglYFMx+7pdpvhFwh7BqisU h/XwAzVHdGlGWh2YgBh9pdbCR9AAMjXAGJSi3AnY61+pPq+Fkyz+BmPmXZfvK4vV vDKz1+y/cmSkjuNqm2J4lUfjxa3FlKPmoPr4sPZiAF39lrR/zqLpgDi2OCfnvvWT AvTcGzzyYLqo4ntJjhsgCeo18ha4xrfgxZcOy9BJglBfpnfccuEg4Fr2FVUZn33C KPbbGOPaBXp44aNpz1h5a3eBy0rQTePrDf/pxa1acMD/O41anUEWn4GkvSOv4fDA V9ZREt4IPDQRoleWYBlQwPqmDpGLfNaiwE77gPoCIrCrxiea78C3C2bTP5qGqJ/k ZySHaXqYNpsCwSoYYT9OXs8pW5aP47OmXyTMQ2etjkajSPOKIAFsvkVY4+s87yL2 Vv43YYwISZeRYXrppl3xYSp61AG0GXChbTeMousOETJYnzJdZdLb0k24eot85ZbV 5QKFNkEsgsquMaEH/TErYvAWlwYbFIWfnqmZLbo1bxD1yXUOPdASr/aVtHPqy/KR YJW4DQBBnuNbz4R+02PzmYIj1sFCKE7dihzlDMas0nUrxFXomR0= =D7Vp -----END PGP SIGNATURE-----