Hmm, I do see a matching checksum
(6d38668862bf9772c0c1c1e0f26aa5dedea9825b33f763b81ccc4aa63df2cef9) for
go1.18.8.windows-amd64.msi.

On Tue, Nov 1, 2022 at 10:28 AM Wojciech Kaczmarek <wojtek...@gmail.com> wrote:
>
> I think it's important to report that  go1.18.8.windows-amd64.msi doesn't 
> match the published sha256 checksum.
>
>
> wtorek, 1 listopada 2022 o 18:01:35 UTC+1 anno...@golang.org napisaƂ(a):
>>
>> Hello gophers,
>>
>> We have just released Go versions 1.19.3 and 1.18.8, minor point releases.
>>
>> These minor releases include 1 security fixes following the security policy:
>>
>> syscall, os/exec: unsanitized NUL in environment variables
>>
>> On Windows, syscall.StartProcess and os/exec.Cmd did not properly check for 
>> invalid environment variable values. A malicious environment variable value 
>> could exploit this behavior to set a value for a different environment 
>> variable. For example, the environment variable string "A=B\x00C=D" set the 
>> variables "A=B" and "C=D".
>>
>> Thanks to RyotaK (https://twitter.com/ryotkak) for reporting this issue.
>>
>> This is CVE-2022-41716 and Go issue https://go.dev/issue/56284.
>>
>> View the release notes for more information:
>> https://go.dev/doc/devel/release#go1.19.3
>>
>> You can download binary and source distributions from the Go website:
>> https://go.dev/dl/
>>
>> To compile from source using a Git clone, update to the release with
>> git checkout go1.19.3 and build as usual.
>>
>> Thanks to everyone who contributed to the releases.
>>
>> Cheers,
>> Matthew and Heschi for the Go team
>
> --
> You received this message because you are subscribed to the Google Groups 
> "golang-nuts" group.
> To unsubscribe from this group and stop receiving emails from it, send an 
> email to golang-nuts+unsubscr...@googlegroups.com.
> To view this discussion on the web visit 
> https://groups.google.com/d/msgid/golang-nuts/b3a092a1-38a2-452b-9451-ceda7ab0cdcdn%40googlegroups.com.

-- 
You received this message because you are subscribed to the Google Groups 
"golang-nuts" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to golang-nuts+unsubscr...@googlegroups.com.
To view this discussion on the web visit 
https://groups.google.com/d/msgid/golang-nuts/CAGeFq%2Bk4pq%3DThKCq%3DUgd21vQ7NWn8p_GnTaApyyK6GLzpTekbQ%40mail.gmail.com.

Reply via email to