Received: from localhost (localhost [127.0.0.1]) by mail.netbsd.org (Postfix) with ESMTP id 9F72284E64 for ; Fri, 8 Sep 2023 13:06:30 +0000 (UTC) X-Virus-Scanned: amavisd-new at netbsd.org Received: from mail.netbsd.org ([IPv6:::1]) by localhost (mail.netbsd.org [IPv6:::1]) (amavisd-new, port 10025) with ESMTP id VsP6LAzxdyEo for ; Fri, 8 Sep 2023 13:06:29 +0000 (UTC) Received: from cvs.NetBSD.org (ivanova.netbsd.org [199.233.217.197]) by mail.netbsd.org (Postfix) with ESMTP id A2E8084CE8 for ; Fri, 8 Sep 2023 13:06:29 +0000 (UTC) Received: by cvs.NetBSD.org (Postfix, from userid 500) id 9C32BFBDB; Fri, 8 Sep 2023 13:06:29 +0000 (UTC) Content-Transfer-Encoding: 7bit Content-Type: multipart/mixed; boundary="_----------=_1694178389241080" MIME-Version: 1.0 Date: Fri, 8 Sep 2023 13:06:29 +0000 From: "Benny Siegert" Subject: CVS commit: pkgsrc/lang To: pkgsrc-changes@NetBSD.org Approved: commit_and_comment Reply-To: bsiegert@netbsd.org X-Mailer: log_accum Message-Id: <20230908130629.9C32BFBDB@cvs.NetBSD.org> This is a multi-part message in MIME format. --_----------=_1694178389241080 Content-Disposition: inline Content-Transfer-Encoding: 8bit Content-Type: text/plain; charset="US-ASCII" Module Name: pkgsrc Committed By: bsiegert Date: Fri Sep 8 13:06:29 UTC 2023 Modified Files: pkgsrc/lang/go: version.mk pkgsrc/lang/go121: PLIST distinfo Log Message: go121: update to 1.21.1 (security) This minor releases includes 4 security fixes following the security policy: - cmd/go: go.mod toolchain directive allows arbitrary execution The go.mod toolchain directive, introduced in Go 1.21, could be leveraged to execute scripts and binaries relative to the root of the module when the "go" command was executed within the module. This applies to modules downloaded using the "go" command from the module proxy, as well as modules downloaded directly using VCS software. Thanks to Juho Nurminen of Mattermost for reporting this issue. This is CVE-2023-39320 and Go issue https://go.dev/issue/62198. - html/template: improper handling of HTML-like comments within script contexts The html/template package did not properly handle HMTL-like "" comment tokens, nor hashbang "#!" comment tokens, in