Bug#820369: [pkg-golang-devel] Bug#820369: golang: CVE-2016-3959: infinite loop in several big integer routines

2016-04-12 Thread Tianon Gravi
found 820369 golang/2:1.3.3-1 thanks On 8 April 2016 at 09:25, Tianon Gravi wrote: > (Go 1.5.4 and Go 1.6.1 will be released on Wednesday April 13 at > approximately 2am UTC) I've uploaded 1.6.1 to unstable, but attached is a patch which appears to apply cleanly against jessie's 1.3.3 (only modi

Bug#820369: [pkg-golang-devel] Bug#820369: golang: CVE-2016-3959: infinite loop in several big integer routines

2016-04-08 Thread Tianon Gravi
On 7 April 2016 at 12:01, Salvatore Bonaccorso wrote: > the following vulnerability was published for golang. > > CVE-2016-3959[0]: > infinite loop in several big integer routines The official "new release" pre-announcement is up now: https://groups.google.com/d/topic/golang-announce/MmSbFHLPo8g/

Bug#820369: golang: CVE-2016-3959: infinite loop in several big integer routines

2016-04-07 Thread Salvatore Bonaccorso
Source: golang Version: 2:1.6-1 Severity: important Tags: security upstream Hi, the following vulnerability was published for golang. CVE-2016-3959[0]: infinite loop in several big integer routines If you fix the vulnerability please also make sure to include the CVE (Common Vulnerabilities &