RHSA-2020:3665: Moderate: go-toolset:rhel8 security update
Go Toolset provides the Go programming language tools and libraries. Go is alternatively known as golang.Security Fix(es): golang.org/x/text: possibility to trigger an infinite loop in encoding/unicode could lead to crash (CVE-2020-14040) golang: data race in certain net/http servers including ReverseProxy can lead to DoS (CVE-2020-15586) golang: ReadUvarint and ReadVarint can read an unlimited number of bytes from invalid inputs (CVE-2020-16845) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2020:3665?
The severity of RHSA-2020:3665 has been classified as moderate.
How do I fix RHSA-2020:3665?
You can fix RHSA-2020:3665 by updating to the corrected version of the affected packages as specified in the advisory.
What vulnerabilities are addressed in RHSA-2020:3665?
RHSA-2020:3665 addresses CVE-2020-14040, which allows an infinite loop in encoding/unicode leading to potential crashes.
Which packages are affected by RHSA-2020:3665?
RHSA-2020:3665 affects multiple packages including golang, go-toolset, and delve among others.
Is there a workaround for RHSA-2020:3665?
There are no published workarounds for RHSA-2020:3665; upgrading to the fixed versions is recommended.