The following builds have been pushed to Fedora EPEL 6 updates-testing
drupal7-7.74-1.el6
golang-1.15.5-1.el6
Details about builds:
================================================================================
drupal7-7.74-1.el6 (FEDORA-EPEL-2020-bc1fdbed24)
An open-source content-management platform
--------------------------------------------------------------------------------
Update Information:
-
https://www.drupal.org/project/drupal/releases/7.74 -
https://www.drupal.org/sa-core-2020-012 -
https://www.drupal.org/project/drupal/releases/7.73 -
https://www.drupal.org/sa-core-2020-007
--------------------------------------------------------------------------------
ChangeLog:
* Wed Nov 18 2020 Shawn Iwinski <shawn.iwinski(a)gmail.com> - 7.74-1
- Update to 7.74
- SA-CORE-2020-007 / CVE-2020-13666
- SA-CORE-2020-012 / CVE-2020-13671
--------------------------------------------------------------------------------
================================================================================
golang-1.15.5-1.el6 (FEDORA-EPEL-2020-3012d075c2)
The Go Programming Language
--------------------------------------------------------------------------------
Update Information:
* Rebase to go1.15.5 * Security fix for CVE-2020-28362, CVE-2020-28367 and
CVE-2020-28366
--------------------------------------------------------------------------------
ChangeLog:
* Mon Nov 16 2020 Jakub ��ajka <jcajka(a)redhat.com> - 1.15.5-1
- Rebase to go1.15.5
- Security fix for CVE-2020-28362, CVE-2020-28367 and CVE-2020-28366
- Resolves: BZ#1897637, BZ#1897645 and BZ#1897648
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1897635 - CVE-2020-28362 golang: math/big: panic during recursive division of
very large numbers
https://bugzilla.redhat.com/show_bug.cgi?id=1897635
[ 2 ] Bug #1897643 - CVE-2020-28366 golang: malicious symbol names can lead to code
execution at build time
https://bugzilla.redhat.com/show_bug.cgi?id=1897643
[ 3 ] Bug #1897646 - CVE-2020-28367 golang: improper validation of cgo flags can lead to
code execution at build time
https://bugzilla.redhat.com/show_bug.cgi?id=1897646
--------------------------------------------------------------------------------