Please unblock package golang-1.19
[ Reason ]
Two upstream minor versions, fixing 5 CVEs
+ CVE-2023-24532: crypto/elliptic: incorrect P-256 ScalarMult and
ScalarBaseMult results
+ CVE-2023-24537: go/parser: infinite loop in parsing
+ CVE-2023-24538: html/template: backticks not treated as string delimiters
+ CVE-2023-24534: net/http, net/textproto: denial of service from excessive
memory allocation
+ CVE-2023-24536: net/http, net/textproto, mime/multipart: denial of
service from excessive resource consumption
[ Impact ]
Several security issues in the Go standard libraries.
[ Tests ]
Besise the unittests upstream added in the new release, I have use the new
version to build some Go packages. And the result is good.
[ Risks ]
Toolchain package and no autopkgtest.
[ Checklist ]
[x] all changes are documented in the d/changelog
[x] I reviewed all changes and I approve them
[x] attach debdiff against the package in testing
I attached the debdiff with
filterdiff --exclude '*_test.go' --exclude '*_windows*' --exclude '*/testdata/*' \
--exclude '*/go.mod' --exclude '*/go.sum' --exclude '*/modules.txt'
[ Other info ]
It may be the last golang-1.19 version to be uploaded during freeze.
The next release is expected (if no urgent CVE happens) to be May, which
is probably hard-freeze time.
unblock golang-1.19/1.19.8-2