Opened 4 months ago

Closed 4 months ago

Last modified 3 months ago

#31456 closed task (fixed)

Upgrade go to 1.12.8+

Reported by: dcf Owned by: tbb-team
Priority: Medium Milestone:
Component: Applications/Tor Browser Version:
Severity: Normal Keywords: tbb-backported
Cc: Actual Points:
Parent ID: Points:
Reviewer: Sponsor:

Description

1.12.8 is a security release. (As of filing this ticket, 1.12.9 is available.)

https://groups.google.com/d/msg/golang-announce/65QixT3tcmg/DrFiG6vvCwAJ

We have just released Go 1.12.8 and Go 1.11.13 to address recently reported security issues. We recommend that all users update to one of these releases (if you’re not sure which, choose Go 1.12.8).

  • net/http: Denial of Service vulnerabilities in the HTTP/2 implementation

net/http and golang.org/x/net/http2 servers that accept direct connections from untrusted clients could be remotely made to allocate an unlimited amount of memory, until the program crashes. Servers will now close connections if the send queue accumulates too many control messages.

The issues are CVE-2019-9512 and CVE-2019-9514, and Go issue golang.org/issue/33606.

This is also fixed in version v0.0.0-20190813141303-74dc4d7220e7 of golang.org/x/net/http2.

  • net/url: parsing validation issue

url.Parse would accept URLs with malformed hosts, such that the Host field could have arbitrary suffixes that would appear in neither Hostname() nor Port(), allowing authorization bypasses in certain applications. Note that URLs with invalid, not numeric ports will now return an error from url.Parse.

The issue is CVE-2019-14809 and Go issue golang.org/issue/29098.

Child Tickets

Change History (4)

comment:1 Changed 4 months ago by gk

I'll prepare a patch for that over in #31465.

comment:2 Changed 4 months ago by boklm

Fixed in master with commit 15d4645a678b12e093f5db89f60f726275f508f6.

Is that something we want to backport to the maint-8.0 branch?

comment:3 Changed 4 months ago by gk

Keywords: tbb-backport added
Resolution: fixed
Status: newclosed

Yes, we want it in the next alpha and stable.

comment:4 Changed 3 months ago by gk

Keywords: tbb-backported added; tbb-backport removed

Backported in commit c8b281ca4609c3d86b30f102f90a26440679c3ea on maint-8.5.

Note: See TracTickets for help on using tickets.