From bd7908c6630f38067350d396ac5d18c3cc2434a0 Mon Sep 17 00:00:00 2001 From: V3n3RiX Date: Sun, 29 Oct 2017 11:22:34 +0000 Subject: gentoo resync : 29.10.2017 --- metadata/glsa/glsa-201710-23.xml | 55 ++++++++++++++++++++++++++++++++++++++++ 1 file changed, 55 insertions(+) create mode 100644 metadata/glsa/glsa-201710-23.xml (limited to 'metadata/glsa/glsa-201710-23.xml') diff --git a/metadata/glsa/glsa-201710-23.xml b/metadata/glsa/glsa-201710-23.xml new file mode 100644 index 000000000000..cc6aa8ba3a3b --- /dev/null +++ b/metadata/glsa/glsa-201710-23.xml @@ -0,0 +1,55 @@ + + + + Go: Multiple vulnerabilities + Multiple vulnerabilities have been found in Go, the worst of which + may result in the execution of arbitrary commands. + + go + 2017-10-23 + 2017-10-23: 1 + 632408 + remote + + + 1.9.1 + 1.9.1 + + + +

Go is an open source programming language that makes it easy to build + simple, reliable, and efficient software. +

+
+ +

Multiple vulnerabilities have been discovered in Go. Please review the + references below for details. +

+
+ +

Remote attackers could execute arbitrary Go commands or conduct a man in + the middle attack. +

+
+ +

There is no known workaround at this time.

+
+ +

All Go users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose ">=dev-lang/go-1.9.1" + +
+ + + CVE-2017-15041 + + + CVE-2017-15042 + + + chrisadr + b-man +
-- cgit v1.2.3