{"schema_version":"1.7.3","id":"SUSE-SU-2019:2940-1","published":"2019-11-11T12:06:36Z","modified":"2026-02-04T02:59:44.513142Z","related":["CVE-2019-16276","CVE-2019-17596"],"upstream":["CVE-2019-16276","CVE-2019-17596"],"summary":"Security update for go1.12","details":"This update for go1.12 fixes the following issues:\n\nSecurity issues fixed:\n\n- CVE-2019-16276: Fixed the handling of invalid HTTP headers, which had allowed request smuggling (bsc#1152082).\n- CVE-2019-17596: Fixed a panic in dsa.Verify caused by invalid public keys (bsc#1154402).\n\nNon-security issue fixed:\n\n- Go was updated to version 1.12.12 (bsc#1141689).\n","references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2019/suse-su-20192940-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1141689"},{"type":"REPORT","url":"https://bugzilla.suse.com/1152082"},{"type":"REPORT","url":"https://bugzilla.suse.com/1154402"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-16276"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-17596"}]}