]> rtime.felk.cvut.cz Git - coffee/buildroot.git/commit
go: security bump to version 1.10.2
authorAnisse Astier <anisse@astier.eu>
Fri, 11 May 2018 20:50:37 +0000 (22:50 +0200)
committerThomas Petazzoni <thomas.petazzoni@bootlin.com>
Fri, 11 May 2018 21:10:27 +0000 (23:10 +0200)
commit81815b85a20d09b8346322ad025c2bb430d17ed3
tree6c47e418365c6f7fec723a3d9461f2269bf612f0
parent486334dd819b15943b6f9e93868a354be0b8ab20
go: security bump to version 1.10.2

This bump contains many bug fixes, as well as the following security
issue, patched in Go 1.10.1:

CVE-2018-7187: The "go get" implementation in Go 1.9.4, when the
-insecure command-line option is used, does not validate the import path
(get/vcs.go only checks for "://" anywhere in the string), which allows
remote attackers to execute arbitrary OS commands via a crafted web
site.

Signed-off-by: Anisse Astier <anisse@astier.eu>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
package/go/go.hash
package/go/go.mk