summaryrefslogtreecommitdiff
path: root/games/scummvm-bass
diff options
context:
space:
mode:
authorbsiegert <bsiegert@pkgsrc.org>2016-12-04 16:08:55 +0000
committerbsiegert <bsiegert@pkgsrc.org>2016-12-04 16:08:55 +0000
commitf027972d5f8c3be64458edfd72c5599cc4afc1d8 (patch)
treef400fc4bf3ec93f0b2dca5e4b1fa0fc176161bdc /games/scummvm-bass
parent3cc22d9bc0d3f792790bad66d97961d6e764e95d (diff)
downloadpkgsrc-f027972d5f8c3be64458edfd72c5599cc4afc1d8.tar.gz
Update Go to 1.7.4.
Two security-related issues were recently reported, and to address these issues we have just released Go 1.6.4 and Go 1.7.4. We recommend that all users update to one of these releases (if you're not sure which, choose Go 1.7.4). The issues addressed by these releases are: On Darwin, user's trust preferences for root certificates were not honored. If the user had a root certificate loaded in their Keychain that was explicitly not trusted, a Go program would still verify a connection using that root certificate. This is addressed by https://golang.org/cl/33721, tracked in https://golang.org/issue/18141. Thanks to Xy Ziemba for identifying and reporting this issue. The net/http package's Request.ParseMultipartForm method starts writing to temporary files once the request body size surpasses the given "maxMemory" limit. It was possible for an attacker to generate a multipart request crafted such that the server ran out of file descriptors. This is addressed by https://golang.org/cl/30410, tracked in https://golang.org/issue/17965. Thanks to Simon Rawet for the report.
Diffstat (limited to 'games/scummvm-bass')
0 files changed, 0 insertions, 0 deletions