Debian Package Tracker
Register | Log in
Subscribe

golang-github-sigstore-timestamp-authority

Sigstore RFC3161 Timestamp Authority (Go library)

Choose email to subscribe with

general
  • source: golang-github-sigstore-timestamp-authority (main)
  • version: 2.0.3-2
  • maintainer: Debian Go Packaging Team (DMD)
  • uploaders: Simon Josefsson [DMD]
  • arch: all
  • std-ver: 4.7.2
  • VCS: Git (Browse, QA)
versions [more versions can be listed by madison] [old versions available from snapshot.debian.org]
[pool directory]
  • stable: 1.2.3-2
  • testing: 2.0.3-2
  • unstable: 2.0.3-2
versioned links
  • 1.2.3-2: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 2.0.3-2: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
binaries
  • golang-github-sigstore-timestamp-authority-dev
action needed
A new upstream version is available: 2.0.4 high
A new upstream version 2.0.4 is available, you should consider packaging it.
Created: 2025-12-17 Last update: 2025-12-17 16:18
1 low-priority security issue in trixie low

There is 1 open security issue in trixie.

1 issue left for the package maintainer to handle:
  • CVE-2025-66564: (needs triaging) Sigstore Timestamp Authority is a service for issuing RFC 3161 timestamps. Prior to 2.0.3, Function api.ParseJSONRequest currently splits (via a call to strings.Split) an optionally-provided OID (which is untrusted data) on periods. Similarly, function api.getContentType splits the Content-Type header (which is also untrusted data) on an application string. As a result, in the face of a malicious request with either an excessively long OID in the payload containing many period characters or a malformed Content-Type header, a call to api.ParseJSONRequest or api.getContentType incurs allocations of O(n) bytes (where n stands for the length of the function's argument). This vulnerability is fixed in 2.0.3.

You can find information about how to handle this issue in the security team's documentation.

Created: 2025-12-05 Last update: 2025-12-15 13:30
news
[rss feed]
  • [2025-12-16] golang-github-sigstore-timestamp-authority 2.0.3-2 MIGRATED to testing (Debian testing watch)
  • [2025-12-13] Accepted golang-github-sigstore-timestamp-authority 2.0.3-2 (source) into unstable (Simon Josefsson)
  • [2025-12-13] golang-github-sigstore-timestamp-authority 2.0.3-1 MIGRATED to testing (Debian testing watch)
  • [2025-12-11] Accepted golang-github-sigstore-timestamp-authority 2.0.3-1 (source) into unstable (Simon Josefsson)
  • [2025-10-04] golang-github-sigstore-timestamp-authority 1.2.9-1 MIGRATED to testing (Debian testing watch)
  • [2025-10-01] Accepted golang-github-sigstore-timestamp-authority 1.2.9-1 (source) into unstable (Simon Josefsson)
  • [2024-11-15] golang-github-sigstore-timestamp-authority 1.2.3-2 MIGRATED to testing (Debian testing watch)
  • [2024-11-13] Accepted golang-github-sigstore-timestamp-authority 1.2.3-2 (source) into unstable (Simon Josefsson)
  • [2024-11-12] Accepted golang-github-sigstore-timestamp-authority 1.2.3-1 (source all) into unstable (Debian FTP Masters) (signed by: Simon Josefsson)
bugs [bug history graph]
  • all: 0
links
  • homepage
  • lintian
  • buildd: logs, reproducibility
  • popcon
  • browse source code
  • edit tags
  • other distros
  • security tracker
  • debian patches
  • debci
ubuntu Ubuntu logo [Information about Ubuntu for Debian Developers]
  • version: 2.0.3-2

Debian Package Tracker — Copyright 2013-2025 The Distro Tracker Developers
Report problems to the tracker.debian.org pseudo-package in the Debian BTS.
Documentation — Bugs — Git Repository — Contributing