Search CVE reports
1 – 10 of 54 results
os.OpenFile(path, os.O_CREATE|O_EXCL) behaved differently on Unix and Windows systems when the target path was a dangling symlink. On Unix systems, OpenFile with O_CREATE and O_EXCL flags never follows symlinks. On Windows, when...
15 affected packages
golang, golang-1.10, golang-1.13, golang-1.14, golang-1.16...
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
golang | Not in release | Not in release | — | — |
golang-1.10 | Not in release | Not in release | — | Ignored |
golang-1.13 | Not in release | Ignored | Ignored | Ignored |
golang-1.14 | Not in release | Not in release | Ignored | — |
golang-1.16 | Not in release | Not in release | Ignored | Ignored |
golang-1.17 | Not in release | Ignored | — | — |
golang-1.18 | Not in release | Ignored | — | Ignored |
golang-1.20 | Not in release | Ignored | — | — |
golang-1.21 | Ignored | Ignored | — | — |
golang-1.22 | Ignored | Ignored | — | — |
golang-1.23 | Ignored | Ignored | — | — |
golang-1.24 | Not in release | Not in release | — | — |
golang-1.6 | Not in release | Not in release | — | — |
golang-1.8 | Not in release | Not in release | — | Ignored |
golang-1.9 | Not in release | Not in release | — | Ignored |
Some fixes available 3 of 28
Proxy-Authorization and Proxy-Authenticate headers persisted on cross-origin redirects potentially leaking sensitive information.
15 affected packages
golang, golang-1.10, golang-1.13, golang-1.14, golang-1.16...
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
golang | Not in release | Not in release | — | — |
golang-1.10 | Not in release | Not in release | — | Needs evaluation |
golang-1.13 | Not in release | Needs evaluation | Needs evaluation | Needs evaluation |
golang-1.14 | Not in release | Not in release | Needs evaluation | — |
golang-1.16 | Not in release | Not in release | Needs evaluation | Needs evaluation |
golang-1.17 | Not in release | Needs evaluation | — | — |
golang-1.18 | Not in release | Needs evaluation | — | Needs evaluation |
golang-1.20 | Not in release | Needs evaluation | — | — |
golang-1.21 | Needs evaluation | Needs evaluation | — | — |
golang-1.22 | Fixed | Fixed | — | — |
golang-1.23 | Needs evaluation | Needs evaluation | — | — |
golang-1.24 | Not in release | Not in release | — | — |
golang-1.6 | Not in release | Not in release | — | — |
golang-1.8 | Not in release | Not in release | — | Needs evaluation |
golang-1.9 | Not in release | Not in release | — | Needs evaluation |
Calling Verify with a VerifyOptions.KeyUsages that contains ExtKeyUsageAny unintentionally disabledpolicy validation. This only affected certificate chains which contain policy graphs, which are rather uncommon.
15 affected packages
golang, golang-1.10, golang-1.13, golang-1.14, golang-1.16...
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
golang | Not in release | Not in release | — | — |
golang-1.10 | Not in release | Not in release | — | Needs evaluation |
golang-1.13 | Not in release | Needs evaluation | Needs evaluation | Needs evaluation |
golang-1.14 | Not in release | Not in release | Needs evaluation | — |
golang-1.16 | Not in release | Not in release | Needs evaluation | Needs evaluation |
golang-1.17 | Not in release | Needs evaluation | — | — |
golang-1.18 | Not in release | Needs evaluation | — | Needs evaluation |
golang-1.20 | Not in release | Needs evaluation | — | — |
golang-1.21 | Needs evaluation | Needs evaluation | — | — |
golang-1.22 | Not affected | Not affected | — | — |
golang-1.23 | Needs evaluation | Needs evaluation | — | — |
golang-1.24 | Not in release | Not in release | — | — |
golang-1.6 | Not in release | Not in release | — | — |
golang-1.8 | Not in release | Not in release | — | Needs evaluation |
golang-1.9 | Not in release | Not in release | — | Needs evaluation |
Some fixes available 3 of 28
Matching of hosts against proxy patterns can improperly treat an IPv6 zone ID as a hostname component. For example, when the NO_PROXY environment variable is set to ”*.example.com”, a request to ”[::1%25.example.com]:80` will...
15 affected packages
golang, golang-1.10, golang-1.13, golang-1.14, golang-1.16...
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
golang | Not in release | Not in release | Not in release | — |
golang-1.10 | Not in release | Not in release | Not in release | Needs evaluation |
golang-1.13 | Not in release | Needs evaluation | Needs evaluation | Needs evaluation |
golang-1.14 | Not in release | Not in release | Needs evaluation | — |
golang-1.16 | Not in release | Not in release | Needs evaluation | Needs evaluation |
golang-1.17 | Not in release | Needs evaluation | Not in release | — |
golang-1.18 | Not in release | Needs evaluation | Not in release | Needs evaluation |
golang-1.20 | Not in release | Needs evaluation | Not in release | — |
golang-1.21 | Needs evaluation | Needs evaluation | Not in release | — |
golang-1.22 | Fixed | Fixed | Not in release | — |
golang-1.23 | Needs evaluation | Needs evaluation | Not in release | — |
golang-1.24 | Not in release | Not in release | Not in release | — |
golang-1.6 | Not in release | Not in release | Not in release | — |
golang-1.8 | Not in release | Not in release | Not in release | Needs evaluation |
golang-1.9 | Not in release | Not in release | Not in release | Needs evaluation |
Some fixes available 3 of 28
Due to the usage of a variable time instruction in the assembly implementation of an internal function, a small number of bits of secret scalars are leaked on the ppc64le architecture. Due to the way this function is used, we do...
15 affected packages
golang, golang-1.10, golang-1.13, golang-1.14, golang-1.16...
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
golang | Not in release | Not in release | Not in release | — |
golang-1.10 | Not in release | Not in release | Not in release | Needs evaluation |
golang-1.13 | Not in release | Needs evaluation | Needs evaluation | Needs evaluation |
golang-1.14 | Not in release | Not in release | Needs evaluation | — |
golang-1.16 | Not in release | Not in release | Needs evaluation | Needs evaluation |
golang-1.17 | Not in release | Needs evaluation | Not in release | — |
golang-1.18 | Not in release | Needs evaluation | Not in release | Needs evaluation |
golang-1.20 | Not in release | Needs evaluation | Not in release | — |
golang-1.21 | Needs evaluation | Needs evaluation | Not in release | — |
golang-1.22 | Fixed | Fixed | Not in release | — |
golang-1.23 | Needs evaluation | Needs evaluation | Not in release | — |
golang-1.24 | Not in release | Not in release | Not in release | — |
golang-1.6 | Not in release | Not in release | Not in release | — |
golang-1.8 | Not in release | Not in release | Not in release | Needs evaluation |
golang-1.9 | Not in release | Not in release | Not in release | Needs evaluation |
Some fixes available 3 of 43
A certificate with a URI which has a IPv6 address with a zone ID may incorrectly satisfy a URI name constraint that applies to the certificate chain. Certificates containing URIs are not permitted in the web PKI, so this only...
18 affected packages
golang, golang-1.10, golang-1.13, golang-1.14, golang-1.16...
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
golang | Not in release | Not in release | Not in release | — |
golang-1.10 | Not in release | Not in release | Not in release | Needs evaluation |
golang-1.13 | Not in release | Needs evaluation | Needs evaluation | Needs evaluation |
golang-1.14 | Not in release | Not in release | Needs evaluation | — |
golang-1.16 | Not in release | Not in release | Needs evaluation | Needs evaluation |
golang-1.17 | Not in release | Needs evaluation | Not in release | — |
golang-1.18 | Not in release | Needs evaluation | Not in release | Needs evaluation |
golang-1.20 | Not in release | Needs evaluation | Not in release | — |
golang-1.21 | Needs evaluation | Needs evaluation | Not in release | — |
golang-1.22 | Fixed | Fixed | Not in release | — |
golang-1.23 | Needs evaluation | Needs evaluation | Not in release | — |
golang-1.24 | Not in release | Not in release | Not in release | — |
golang-1.6 | Not in release | Not in release | Not in release | — |
golang-1.8 | Not in release | Not in release | Not in release | Needs evaluation |
golang-1.9 | Not in release | Not in release | Not in release | Needs evaluation |
golang-go.crypto | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
lxd | Not in release | Not in release | Not affected | Needs evaluation |
snapd | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
Some fixes available 3 of 27
The HTTP client drops sensitive headers after following a cross-domain redirect. For example, a request to a.com/ containing an Authorization header which is redirected to b.com/ will not send that header to b.com. In the event...
16 affected packages
golang, golang-1.10, golang-1.13, golang-1.14, golang-1.16...
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
golang | Not in release | Not in release | Not in release | Not in release |
golang-1.10 | Not in release | Not in release | Not in release | Needs evaluation |
golang-1.13 | Not in release | Needs evaluation | Needs evaluation | Needs evaluation |
golang-1.14 | Not in release | Not in release | Needs evaluation | Not in release |
golang-1.16 | Not in release | Not in release | Needs evaluation | Needs evaluation |
golang-1.17 | Not in release | Needs evaluation | Not in release | Not in release |
golang-1.18 | Not in release | Needs evaluation | Not in release | Needs evaluation |
golang-1.19 | Not in release | Not in release | Not in release | Not in release |
golang-1.20 | Not in release | Needs evaluation | Not in release | Not in release |
golang-1.21 | Needs evaluation | Needs evaluation | Not in release | Not in release |
golang-1.22 | Fixed | Fixed | Not in release | — |
golang-1.23 | Needs evaluation | Needs evaluation | Not in release | — |
golang-1.24 | Not in release | Not in release | Not in release | — |
golang-1.6 | Not in release | Not in release | Not in release | Not in release |
golang-1.8 | Not in release | Not in release | Not in release | Needs evaluation |
golang-1.9 | Not in release | Not in release | Not in release | Needs evaluation |
Using ParsePKCS1PrivateKey to parse a RSA key that is missing the CRT values would panic when verifying that the key is well formed.
15 affected packages
golang, golang-1.10, golang-1.13, golang-1.14, golang-1.16...
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
golang | Not in release | Not in release | Not in release | — |
golang-1.10 | Not in release | Not in release | Not in release | Needs evaluation |
golang-1.13 | Not in release | Needs evaluation | Needs evaluation | Needs evaluation |
golang-1.14 | Not in release | Not in release | Needs evaluation | — |
golang-1.16 | Not in release | Not in release | Needs evaluation | Needs evaluation |
golang-1.17 | Not in release | Needs evaluation | Not in release | — |
golang-1.18 | Not in release | Needs evaluation | Not in release | Needs evaluation |
golang-1.20 | Not in release | Needs evaluation | Not in release | — |
golang-1.21 | Needs evaluation | Needs evaluation | Not in release | — |
golang-1.22 | Not affected | Not affected | Not in release | — |
golang-1.23 | Needs evaluation | Needs evaluation | Not in release | — |
golang-1.24 | Not in release | Not in release | Not in release | — |
golang-1.6 | Not in release | Not in release | Not in release | — |
golang-1.8 | Not in release | Not in release | Not in release | Needs evaluation |
golang-1.9 | Not in release | Not in release | Not in release | Needs evaluation |
Credentials provided via the new GOAUTH feature were not being properly segmented by domain, allowing a malicious server to request credentials they should not have access to. By default, unless otherwise set, this only affected...
15 affected packages
golang, golang-1.10, golang-1.13, golang-1.14, golang-1.16...
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
golang | Not in release | Not in release | Not in release | — |
golang-1.10 | Not in release | Not in release | Not in release | Needs evaluation |
golang-1.13 | Not in release | Needs evaluation | Needs evaluation | Needs evaluation |
golang-1.14 | Not in release | Not in release | Needs evaluation | — |
golang-1.16 | Not in release | Not in release | Needs evaluation | Needs evaluation |
golang-1.17 | Not in release | Needs evaluation | Not in release | — |
golang-1.18 | Not in release | Needs evaluation | Not in release | Needs evaluation |
golang-1.20 | Not in release | Needs evaluation | Not in release | — |
golang-1.21 | Needs evaluation | Needs evaluation | Not in release | — |
golang-1.22 | Not affected | Not affected | Not in release | — |
golang-1.23 | Needs evaluation | Needs evaluation | Not in release | — |
golang-1.24 | Not in release | Not in release | Not in release | — |
golang-1.6 | Not in release | Not in release | Not in release | — |
golang-1.8 | Not in release | Not in release | Not in release | Needs evaluation |
golang-1.9 | Not in release | Not in release | Not in release | Needs evaluation |
Some fixes available 8 of 24
Calling Parse on a ”// +build” build tag line with deeply nested expressions can cause a panic due to stack exhaustion.
14 affected packages
golang, golang-1.10, golang-1.13, golang-1.14, golang-1.16...
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
golang | Not in release | Not in release | Not in release | — |
golang-1.10 | Not in release | Not in release | Not in release | Needs evaluation |
golang-1.13 | Not in release | Needs evaluation | Needs evaluation | Needs evaluation |
golang-1.14 | Not in release | Not in release | Needs evaluation | — |
golang-1.16 | Not in release | Not in release | Needs evaluation | Needs evaluation |
golang-1.17 | Not in release | Fixed | Not in release | — |
golang-1.18 | Not in release | Fixed | Fixed | Fixed |
golang-1.19 | Not in release | Not in release | Not in release | — |
golang-1.20 | Not in release | Needs evaluation | Not in release | — |
golang-1.21 | Needs evaluation | Needs evaluation | Not in release | — |
golang-1.22 | Fixed | Fixed | Fixed | — |
golang-1.6 | Not in release | Not in release | Not in release | — |
golang-1.8 | Not in release | Not in release | Not in release | Needs evaluation |
golang-1.9 | Not in release | Not in release | Not in release | Needs evaluation |