Accepted golang-1.20 1.20.3-1 (source) into unstable
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256
Format: 1.8
Date: Wed, 05 Apr 2023 02:04:08 +0800
Source: golang-1.20
Architecture: source
Version: 1.20.3-1
Distribution: unstable
Urgency: medium
Maintainer: Debian Go Compiler Team <team+go-compiler@tracker.debian.org>
Changed-By: Shengjing Zhu <zhsj@debian.org>
Changes:
golang-1.20 (1.20.3-1) unstable; urgency=medium
.
* Team upload
* New upstream version 1.20.3
+ CVE-2023-24537: go/parser: infinite loop in parsing
+ CVE-2023-24538: html/template: backticks not treated as string delimiters
+ CVE-2023-24534: net/http, net/textproto: denial of service from excessive
memory allocation
+ CVE-2023-24536: net/http, net/textproto, mime/multipart: denial of
service from excessive resource consumption
Checksums-Sha1:
8e24b1c829f49ee340d5762aaf669401f313f8c6 2234 golang-1.20_1.20.3-1.dsc
facffd4f88ab40f4bb462a93f50f77b114cda7c4 26184364 golang-1.20_1.20.3.orig.tar.gz
51fe4708f2511516274e95564b2bfa3f81f54a6e 819 golang-1.20_1.20.3.orig.tar.gz.asc
bb2f625107b3a44b350d12f2f18827ae225f7e88 37048 golang-1.20_1.20.3-1.debian.tar.xz
f0612fed5f33a85c1f9e9a12f6b27d03a887f3dc 6231 golang-1.20_1.20.3-1_amd64.buildinfo
Checksums-Sha256:
44785113492ec027ed98c1c393d8e1107b2834e216f71e337961bd44dae20406 2234 golang-1.20_1.20.3-1.dsc
e447b498cde50215c4f7619e5124b0fc4e25fb5d16ea47271c47f278e7aa763a 26184364 golang-1.20_1.20.3.orig.tar.gz
ebf41effa9ddc0f56c07bfeb53c65c3e1e34cbb99cff576134eedb6228dd8217 819 golang-1.20_1.20.3.orig.tar.gz.asc
f9aa19e4c184e0c3db8f428740153547b0c05170672e68080e13dc3dc23eed41 37048 golang-1.20_1.20.3-1.debian.tar.xz
6aa983e2f10de5ce5c7cbd137d49fbfb378683a5ca5b8f39e9453a66504f38ff 6231 golang-1.20_1.20.3-1_amd64.buildinfo
Files:
1e2ccbdb8acf180d770bb9e7b53f5384 2234 golang optional golang-1.20_1.20.3-1.dsc
3098587dbbd9676149eeb4fc16d0b207 26184364 golang optional golang-1.20_1.20.3.orig.tar.gz
e32ace69f1303842a864adab73ed9b8e 819 golang optional golang-1.20_1.20.3.orig.tar.gz.asc
066bb3b4e70057b7b8b3bc09bb5be722 37048 golang optional golang-1.20_1.20.3-1.debian.tar.xz
c68b9a4eb16aa8ebc20b93ce5873e150 6231 golang optional golang-1.20_1.20.3-1_amd64.buildinfo
-----BEGIN PGP SIGNATURE-----
iHUEARYIAB0WIQSRhdT1d2eu7mxV1B5/RPol6lUUywUCZCxs8gAKCRB/RPol6lUU
y+qgAPwPha2eb5saTwvWo2tEisSMQ48MNa6iHe0bookzBB8q0wD+Kk/d5ti0du0i
76svccU+dmNmisYX3bWMksk3/rIzlg4=
=tUCy
-----END PGP SIGNATURE-----
Reply to: