ALT-PU-2015-1812-1
Closed vulnerabilities
Modified: 2024-11-21
CVE-2015-5739
The net/http library in net/textproto/reader.go in Go before 1.4.3 does not properly parse HTTP header keys, which allows remote attackers to conduct HTTP request smuggling attacks via a space instead of a hyphen, as demonstrated by "Content Length" instead of "Content-Length."
- FEDORA-2015-15619
- FEDORA-2015-15619
- FEDORA-2015-15618
- FEDORA-2015-15618
- RHSA-2016:1538
- RHSA-2016:1538
- [oss-security] 20150729 CVE Request - Go net/http library - HTTP smuggling
- [oss-security] 20150729 CVE Request - Go net/http library - HTTP smuggling
- [oss-security] 20150804 CVE Request - Go net/http library - HTTP smuggling
- [oss-security] 20150804 CVE Request - Go net/http library - HTTP smuggling
- [oss-security] 20150805 Re: CVE Request - Go net/http library - HTTP smuggling
- [oss-security] 20150805 Re: CVE Request - Go net/http library - HTTP smuggling
- 76281
- 76281
- https://bugzilla.redhat.com/show_bug.cgi?id=1250352
- https://bugzilla.redhat.com/show_bug.cgi?id=1250352
- https://github.com/golang/go/commit/117ddcb83d7f42d6aa72241240af99ded81118e9
- https://github.com/golang/go/commit/117ddcb83d7f42d6aa72241240af99ded81118e9
Modified: 2024-11-21
CVE-2015-5740
The net/http library in net/http/transfer.go in Go before 1.4.3 does not properly parse HTTP headers, which allows remote attackers to conduct HTTP request smuggling attacks via a request with two Content-length headers.
- FEDORA-2015-15619
- FEDORA-2015-15619
- FEDORA-2015-15618
- FEDORA-2015-15618
- RHSA-2016:1538
- RHSA-2016:1538
- [oss-security] 20150729 CVE Request - Go net/http library - HTTP smuggling
- [oss-security] 20150729 CVE Request - Go net/http library - HTTP smuggling
- [oss-security] 20150804 CVE Request - Go net/http library - HTTP smuggling
- [oss-security] 20150804 CVE Request - Go net/http library - HTTP smuggling
- [oss-security] 20150805 Re: CVE Request - Go net/http library - HTTP smuggling
- [oss-security] 20150805 Re: CVE Request - Go net/http library - HTTP smuggling
- https://bugzilla.redhat.com/show_bug.cgi?id=1250352
- https://bugzilla.redhat.com/show_bug.cgi?id=1250352
- https://github.com/golang/go/commit/300d9a21583e7cf0149a778a0611e76ff7c6680f
- https://github.com/golang/go/commit/300d9a21583e7cf0149a778a0611e76ff7c6680f
Modified: 2024-11-21
CVE-2015-5741
The net/http library in net/http/transfer.go in Go before 1.4.3 does not properly parse HTTP headers, which allows remote attackers to conduct HTTP request smuggling attacks via a request that contains Content-Length and Transfer-Encoding header fields.
- http://lists.fedoraproject.org/pipermail/package-announce/2015-October/167997.html
- http://lists.fedoraproject.org/pipermail/package-announce/2015-October/167997.html
- http://lists.fedoraproject.org/pipermail/package-announce/2015-October/168029.html
- http://lists.fedoraproject.org/pipermail/package-announce/2015-October/168029.html
- http://seclists.org/oss-sec/2015/q3/237
- http://seclists.org/oss-sec/2015/q3/237
- http://seclists.org/oss-sec/2015/q3/292
- http://seclists.org/oss-sec/2015/q3/292
- http://seclists.org/oss-sec/2015/q3/294
- http://seclists.org/oss-sec/2015/q3/294
- https://bugzilla.redhat.com/show_bug.cgi?id=1250352
- https://bugzilla.redhat.com/show_bug.cgi?id=1250352
- https://github.com/golang/go/commit/300d9a21583e7cf0149a778a0611e76ff7c6680f
- https://github.com/golang/go/commit/300d9a21583e7cf0149a778a0611e76ff7c6680f
Modified: 2024-11-21
CVE-2016-3959
The Verify function in crypto/dsa/dsa.go in Go before 1.5.4 and 1.6.x before 1.6.1 does not properly check parameters passed to the big integer library, which might allow remote attackers to cause a denial of service (infinite loop) via a crafted public key to a program that uses HTTPS client certificates or SSH server libraries.
- FEDORA-2016-2940ad5550
- FEDORA-2016-2940ad5550
- FEDORA-2016-59c5e405e3
- FEDORA-2016-59c5e405e3
- FEDORA-2016-2fcfc7670f
- FEDORA-2016-2fcfc7670f
- openSUSE-SU-2016:1331
- openSUSE-SU-2016:1331
- RHSA-2016:1538
- RHSA-2016:1538
- [oss-security] 20160405 CVE request - Go - DLL loading, Big int
- [oss-security] 20160405 CVE request - Go - DLL loading, Big int
- [oss-security] 20160405 Re: CVE request - Go - DLL loading, Big int
- [oss-security] 20160405 Re: CVE request - Go - DLL loading, Big int
- https://go-review.googlesource.com/#/c/21533/
- https://go-review.googlesource.com/#/c/21533/
- [golang-announce] 20160412 [security] Go 1.6.1 and 1.5.4 are released
- [golang-announce] 20160412 [security] Go 1.6.1 and 1.5.4 are released