-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Format: 1.8 Date: Wed, 05 Apr 2023 02:04:08 +0800 Source: golang-1.20 Architecture: source Version: 1.20.3-1 Distribution: unstable Urgency: medium Maintainer: Debian Go Compiler Team <team+go-compiler@tracker.debian.org> Changed-By: Shengjing Zhu <zhsj@debian.org> Changes: golang-1.20 (1.20.3-1) unstable; urgency=medium . * Team upload * New upstream version 1.20.3 + CVE-2023-24537: go/parser: infinite loop in parsing + CVE-2023-24538: html/template: backticks not treated as string delimiters + CVE-2023-24534: net/http, net/textproto: denial of service from excessive memory allocation + CVE-2023-24536: net/http, net/textproto, mime/multipart: denial of service from excessive resource consumption Checksums-Sha1: 8e24b1c829f49ee340d5762aaf669401f313f8c6 2234 golang-1.20_1.20.3-1.dsc facffd4f88ab40f4bb462a93f50f77b114cda7c4 26184364 golang-1.20_1.20.3.orig.tar.gz 51fe4708f2511516274e95564b2bfa3f81f54a6e 819 golang-1.20_1.20.3.orig.tar.gz.asc bb2f625107b3a44b350d12f2f18827ae225f7e88 37048 golang-1.20_1.20.3-1.debian.tar.xz f0612fed5f33a85c1f9e9a12f6b27d03a887f3dc 6231 golang-1.20_1.20.3-1_amd64.buildinfo Checksums-Sha256: 44785113492ec027ed98c1c393d8e1107b2834e216f71e337961bd44dae20406 2234 golang-1.20_1.20.3-1.dsc e447b498cde50215c4f7619e5124b0fc4e25fb5d16ea47271c47f278e7aa763a 26184364 golang-1.20_1.20.3.orig.tar.gz ebf41effa9ddc0f56c07bfeb53c65c3e1e34cbb99cff576134eedb6228dd8217 819 golang-1.20_1.20.3.orig.tar.gz.asc f9aa19e4c184e0c3db8f428740153547b0c05170672e68080e13dc3dc23eed41 37048 golang-1.20_1.20.3-1.debian.tar.xz 6aa983e2f10de5ce5c7cbd137d49fbfb378683a5ca5b8f39e9453a66504f38ff 6231 golang-1.20_1.20.3-1_amd64.buildinfo Files: 1e2ccbdb8acf180d770bb9e7b53f5384 2234 golang optional golang-1.20_1.20.3-1.dsc 3098587dbbd9676149eeb4fc16d0b207 26184364 golang optional golang-1.20_1.20.3.orig.tar.gz e32ace69f1303842a864adab73ed9b8e 819 golang optional golang-1.20_1.20.3.orig.tar.gz.asc 066bb3b4e70057b7b8b3bc09bb5be722 37048 golang optional golang-1.20_1.20.3-1.debian.tar.xz c68b9a4eb16aa8ebc20b93ce5873e150 6231 golang optional golang-1.20_1.20.3-1_amd64.buildinfo -----BEGIN PGP SIGNATURE----- iHUEARYIAB0WIQSRhdT1d2eu7mxV1B5/RPol6lUUywUCZCxs8gAKCRB/RPol6lUU y+qgAPwPha2eb5saTwvWo2tEisSMQ48MNa6iHe0bookzBB8q0wD+Kk/d5ti0du0i 76svccU+dmNmisYX3bWMksk3/rIzlg4= =tUCy -----END PGP SIGNATURE-----