[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"repo-stars":3,"vuln-OPENSUSE-SU-2020:1405-1":6},{"stargazers_count":4,"fetched_at":5},7,"2026-06-05T02:55:30.529Z",{"id":7,"descriptions":8,"cisa":9,"weaknesses":10,"exploits":11,"aliases":12,"duplicate_of":9,"upstream":13,"downstream":20,"duplicates":21,"related":22,"reserved_at":9,"published_at":26,"modified_at":27,"state":9,"summary":28,"references_raw":30,"kevs":79,"epss":9,"epss_history":80,"metrics":81,"affected":82},"OPENSUSE-SU-2020:1405-1","Security update for go1.14\n\nThis update for go1.14 fixes the following issues:\n\n- go1.14 was updated to version 1.14.7 \n- CVE-2020-16845: dUvarint and ReadVarint can read an unlimited number of bytes from invalid inputs (bsc#1174977).\t  \n\n- go1.14.6 (released 2020-07-16) includes fixes to the go command,\n  the compiler, the linker, vet, and the database/sql,\n  encoding/json, net/http, reflect, and testing packages.\n  Refs bsc#1164903 go1.14 release tracking\n  Refs bsc#1174153 bsc#1174191\n  * go#39991 runtime: missing deferreturn on linux/ppc64le\n  * go#39920 net/http: panic on misformed If-None-Match Header with http.ServeContent\n  * go#39849 cmd/compile: internal compile error when using sync.Pool: mismatched zero/store sizes\n  * go#39824 cmd/go: TestBuildIDContainsArchModeEnv/386 fails on linux/386 in Go 1.14 and 1.13, not 1.15\n  * go#39698 reflect: panic from malloc after MakeFunc function returns value that is also stored globally\n  * go#39636 reflect: DeepEqual can return true for values that are not equal\n  * go#39585 encoding/json: incorrect object key unmarshaling when using custom TextUnmarshaler as Key with string va\nlues\n  * go#39562 cmd/compile/internal/ssa: TestNexting/dlv-dbg-hist failing on linux-386-longtest builder because it trie\ns to use an older version of dlv which only supports linux/amd64\n  * go#39308 testing: streaming output loses parallel subtest associations\n  * go#39288 cmd/vet: update for new number formats\n  * go#39101 database/sql: context cancellation allows statements to execute after rollback\n  * go#38030 doc: BuildNameToCertificate deprecated in go 1.14 not mentioned in the release notes\n  * go#40212 net/http: Expect 100-continue panics in httputil.ReverseProxy bsc#1174153 CVE-2020-15586\n  * go#40210 crypto/x509: Certificate.Verify method seemingly ignoring EKU requirements on Windows bsc#1174191 CVE-2020-14039 (Windows only)\n- Add patch to ensure /etc/hosts is used if /etc/nsswitch.conf is\n  not present bsc#1172868 gh#golang/go#35305\n\nThis update was imported from the SUSE:SLE-15:Update update project.",null,[],[],[],[14,16,18],{"_key":15},"CVE-2020-14039",{"_key":17},"CVE-2020-15586",{"_key":19},"CVE-2020-16845",[],[],[23,24,25],{"_key":15},{"_key":17},{"_key":19},"2020-09-10T18:24:01Z","2026-02-04T02:50:16.518473Z",{"cisa_kev":29,"cisa_ransomware":29,"cisa_vendor":9,"epss_severity":9,"epss_score":9,"severity":9,"severity_score":9,"severity_version":9,"severity_source":9,"severity_vector":9,"severity_status":9},false,[31,37,42,46,50,54,58,62,66,71,75],{"url":32,"sources":33,"tags":35},"https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/DMSI6TFFNOIMEI3XSXGHKMVCWZP2743Q/",[34],"osv_opensuse",[36],"Advisory",{"url":38,"sources":39,"tags":40},"https://bugzilla.suse.com/1164903",[34],[41],"REPORT",{"url":43,"sources":44,"tags":45},"https://bugzilla.suse.com/1169832",[34],[41],{"url":47,"sources":48,"tags":49},"https://bugzilla.suse.com/1170826",[34],[41],{"url":51,"sources":52,"tags":53},"https://bugzilla.suse.com/1172868",[34],[41],{"url":55,"sources":56,"tags":57},"https://bugzilla.suse.com/1174153",[34],[41],{"url":59,"sources":60,"tags":61},"https://bugzilla.suse.com/1174191",[34],[41],{"url":63,"sources":64,"tags":65},"https://bugzilla.suse.com/1174977",[34],[41],{"url":67,"sources":68,"tags":69},"https://www.suse.com/security/cve/CVE-2020-14039",[34],[70],"WEB",{"url":72,"sources":73,"tags":74},"https://www.suse.com/security/cve/CVE-2020-15586",[34],[70],{"url":76,"sources":77,"tags":78},"https://www.suse.com/security/cve/CVE-2020-16845",[34],[70],[],[],[],[83],{"ecosystem":84,"name":85,"vendor":86,"product":87,"cpe_part":9,"purl_type":88,"purl_namespace":86,"purl_name":87,"source":9,"versions":89},"openSUSE","go1.14","opensuse","go1.14&distro=openSUSE Leap 15.1","rpm",[90],{"version":91,"is_range":92,"range_type":93,"version_start":9,"version_start_type":9,"version_end":94,"version_end_type":95,"fixed_in":9},"lt1_14_7_lp151_13_1",true,"ecosystem","1.14.7-lp151.13.1","excluding"]