安全公告详情

NS-SA-2026-0062

2026-07-27 21:21:37

简介

moderate: binutils/ipv6nat security update

严重级别

moderate

主题

An update for binutils/ipv6nat is now available for NewStart CGSL MAIN 6.06.
NewStart Security has rated this update as having a security impact of moderate. A Common Vunlnerability Scoring System(CVSS)base score, which gives a detailed severity rating, is available for each vulnerability from the CVElink(s) in the References section.

详细描述

binutils:
ipv6nat:


Security Fix(es):
binutils: A flaw was found in GNU Binutils. This vulnerability allows a stack-based buffer overflow via manipulation of the buf argument in the disassemble_bytes function.(CVE-2025-0840)
binutils: bugfix
ipv6nat: It was discovered that net/http (through net/textproto) in golang does not correctly interpret HTTP requests where an HTTP header contains spaces before the colon. This could be abused by an attacker to smuggle HTTP requests when a proxy or a firewall is placed behind a server implemented in Go or to filter bypasses depending on the specific network configuration.(CVE-2019-16276)
ipv6nat: et/url in Go before 1.11.13 and 1.12.x before 1.12.8 mishandles malformed hosts in URLs, leading to an authorization bypass in some applications. This is related to a Host field with a suffix appearing in neither Hostname() nor Port(), and is related to a non-numeric port number. For example, an attacker can compose a crafted javascript:// URL that results in a hostname of google.com.(CVE-2019-14809)
ipv6nat: The crypto/x509 package of Go before 1.10.6 and 1.11.x before 1.11.3 does not limit the amount of work performed for each chain verification, which might allow attackers to craft pathological inputs leading to a CPU denial of service. Go TLS servers accepting client certificates and TLS clients are affected.(CVE-2018-16875)
ipv6nat: Go before 1.10.8 and 1.11.x before 1.11.5 mishandles P-521 and P-384 elliptic curves, which allows attackers to cause a denial of service (CPU consumption) or possibly conduct ECDH private key recovery attacks.(CVE-2019-6486)
ipv6nat: A flaw was found in the math/big package of Go's standard library that causes a denial of service. Applications written in Go that use math/big via cryptographic packages, including crypto/rsa and crypto/x509, are vulnerable and can potentially cause panic via a crafted certificate chain. The highest threat from this vulnerability is to system availability.(CVE-2020-28362)
ipv6nat: A flaw was found in the Go encoding/binary package. Certain invalid inputs to the ReadUvarint or the ReadVarint causes those functions to read an unlimited number of bytes from the ByteReader argument before returning an error. This flaw possibly leads to processing more input than expected. The highest threat from this vulnerability is to system availability.(CVE-2020-16845)
ipv6nat: bugfix


Solution:
For details on how to apply this update, which includes the changes described in this advisory, refer to:
http://security.gd-linux.com/how_to_apply_patch.html
Remember the build tag is 6.06.11B10.

影响组件

  • binutils
  • ipv6nat

影响产品

  • CGSL MAIN 6.06

更新包

{"fix":[{"product":"CGSL MAIN 6.06","pkgs":[{"binary":["binutils-2.30-123.0.1.zncgsl6.t4.0.x86_64.rpm"],"source":"binutils-2.30-123.0.1.zncgsl6.t4.0.src.rpm"},{"binary":["ipv6nat-0.3.2-1.zncgsl6.t20.0.x86_64.rpm"],"source":"ipv6nat-0.3.2-1.zncgsl6.t20.0.src.rpm"}]}]}

CVE

参考