-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Format: 1.8 Date: Sun, 12 Nov 2023 17:17:52 -0700 Source: golang-1.20 Architecture: source Version: 1.20.11-1~bpo12+1 Distribution: bookworm-backports Urgency: medium Maintainer: Debian Go Compiler Team <team+go-compiler@tracker.debian.org> Changed-By: Anthony Fok <foka@debian.org> Changes: golang-1.20 (1.20.11-1~bpo12+1) bookworm-backports; urgency=medium . * Rebuild for bookworm-backports. . golang-1.20 (1.20.11-1) unstable; urgency=medium . * Team upload. * New upstream version 1.20.11 + CVE-2023-45283: path/filepath: recognize \??\ as a Root Local Device path prefix. + CVE-2023-45284: path/filepath: recognize device names with trailing spaces and superscripts. . golang-1.20 (1.20.10-1) unstable; urgency=medium . * Team upload. * New upstream version 1.20.10 + CVE-2023-44487/CVE-2023-39325: net/http: rapid stream resets can cause excessive work . golang-1.20 (1.20.9-1) unstable; urgency=medium . * Team upload. * New upstream version 1.20.9 + CVE-2023-39323: cmd/go: line directives allows arbitrary execution during build . golang-1.20 (1.20.8-1) unstable; urgency=medium . * Team upload. * New upstream version 1.20.8 + CVE-2023-39318: html/template: improper handling of HTML-like comments within script contexts + CVE-2023-39319: html/template: improper handling of special tags within script contexts Checksums-Sha1: 7c7d1802595c1405440df4bad5c437ce0f5e9fcf 2965 golang-1.20_1.20.11-1~bpo12+1.dsc 4505fc6054ea14436ce0d347fbc2f8bf67b1ba37 37924 golang-1.20_1.20.11-1~bpo12+1.debian.tar.xz e620c77c5abdb7d76581abde90b89fd6fcfad643 7131 golang-1.20_1.20.11-1~bpo12+1_amd64.buildinfo Checksums-Sha256: c36e76df67a952563d4b378580659d2ec7d973f33aee695264d129eb1a27c1b1 2965 golang-1.20_1.20.11-1~bpo12+1.dsc dad4bd6c6eada70e47372b639a47b25acc25c320300f4ce964f25a19934bf7bf 37924 golang-1.20_1.20.11-1~bpo12+1.debian.tar.xz 856bf38cc404c604fa8156a5cd2095a2049d008b969887945a9febff4a61ecd0 7131 golang-1.20_1.20.11-1~bpo12+1_amd64.buildinfo Files: 68c27730a018598eadf832b5f36cdeab 2965 golang optional golang-1.20_1.20.11-1~bpo12+1.dsc 392327701fd94a2b63b667044c6d18c0 37924 golang optional golang-1.20_1.20.11-1~bpo12+1.debian.tar.xz 4f3b32f66328c120da896818867cb5ca 7131 golang optional golang-1.20_1.20.11-1~bpo12+1_amd64.buildinfo -----BEGIN PGP SIGNATURE----- iQJEBAEBCAAuFiEEFCQhsZrUqVmW+VBy6iUAtBLFms8FAmVRfZoQHGZva2FAZGVi aWFuLm9yZwAKCRDqJQC0EsWazyKNEACO4V4dFkIlUTnlfUwcBUw0tSN2Otq1bx2v HT9rLB7fEBPEWKz034rS6JwxDLrE9xzsy84Pks4dQvuhHxPsxJ/YdxE/Q3MGkaFi jXIdmRXfRZWdmQRuZ+gXxc1kNNaUWQEuyINY3Z/sd9yT6XKj0Fqrq56JKf3D/PIn J+LaTf5CFQiwkxhXBIOLR8g0RpaFszZOvyqDO9awqHt7vEYIlK1RaEwH3+ELv9K9 X5UOKtXjPH4o7I8TUW1z8mH1Fqs83FY5GqJJBznrkqRbjwv3kEra1icfXsziXc/C lnQG7fZGp5oWdvag6NYlETOInPDHo/dnaPgNMplenarESVSZH5EIU/Aw35gMQF8G ir0X/Het5hGmBi8aAeh23/+awz6xvJF9MikA1/xOXcSY/ehjXNkGGjUF+iNibYns lY3zE5x81Vl6EvPy9ncKYQDdBnX1DFWlQ6n4V/I14qpV/wikSnRw1/XhDL6O/j+E nA6mVst65phWZTEON+nYr9/4rFgW/5uHLeLTHEqlpCg3+xmc+iZDWQSn5H89Syow EKAbrJoRKBtdn/ilaR9aPal0SWFVkdvSfXXOQJ+6SjHVxRPwu0WpFisrSYOsf5ME oPbdeIPQaKjAkg33rT01n0/x2a4Iukz6SdvlA/mxwqfhQKQR96ny1bjF/3TyaBWk s7K02/XHpA== =mTx7 -----END PGP SIGNATURE-----