The Go Programming Language.\r\n\r\n Security Fix(es):\r\n\r\n The encoding/xml package in Go (all versions) does not correctly preserve the semantics of attribute namespace prefixes during tokenization round-trips, which allows an attacker to craft inputs that behave in conflicting ways during different stages of processing in affected downstream applications.(CVE-2020-29509)\r\n\r\n
{ "severity": "Medium" }
{ "aarch64": [ "golang-1.13.15-2.oe1.aarch64.rpm", "golang-1.13.15-2.oe1.aarch64.rpm" ], "src": [ "golang-1.13.15-2.oe1.src.rpm", "golang-1.13.15-2.oe1.src.rpm" ], "x86_64": [ "golang-1.13.15-2.oe1.x86_64.rpm", "golang-1.13.15-2.oe1.x86_64.rpm" ], "noarch": [ "golang-help-1.13.15-2.oe1.noarch.rpm", "golang-devel-1.13.15-2.oe1.noarch.rpm", "golang-help-1.13.15-2.oe1.noarch.rpm", "golang-devel-1.13.15-2.oe1.noarch.rpm" ] }