Bugzilla – Bug 1146123
VUL-0: CVE-2019-14809: go: malformed hosts in URLs leads to authorization bypass
Last modified: 2020-07-29 13:56:30 UTC
CVE-2019-14809 A vulnerability was found in net/url in Go before 1.11.13 and 1.12.x before 1.12.8 mishandles malformed hosts in URLs, leading to an authorization bypass in some applications. This is related to a Host field with a suffix appearing in neither Hostname() nor Port(), and is related to a non-numeric port number. For example, an attacker can compose a crafted javascript:// URL that results in a hostname of google.com. Reference: https://github.com/golang/go/issues/29098 Upstream commit: https://github.com/golang/go/commit/61bb56ad63992a3199acc55b2537c8355ef887b6 References: https://bugzilla.redhat.com/show_bug.cgi?id=1743129 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2019-14809 http://people.canonical.com/~ubuntu-security/cve/2019/CVE-2019-14809.html http://www.debian.org/security/2019/dsa-4503 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-14809 https://github.com/golang/go/issues/29098 https://groups.google.com/forum/#!topic/golang-announce/0uuMm1BwpHE https://groups.google.com/forum/#!topic/golang-announce/65QixT3tcmg
SUSE-SU-2019:2213-1: An update that solves three vulnerabilities and has one errata is now available. Category: security (moderate) Bug References: 1141688,1146111,1146115,1146123 CVE References: CVE-2019-14809,CVE-2019-9512,CVE-2019-9514 Sources used: SUSE Linux Enterprise Module for Open Buildservice Development Tools 15-SP1 (src): go1.11-1.11.13-1.18.1 SUSE Linux Enterprise Module for Open Buildservice Development Tools 15 (src): go1.11-1.11.13-1.18.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
SUSE-SU-2019:2214-1: An update that solves three vulnerabilities and has two fixes is now available. Category: security (moderate) Bug References: 1139210,1141689,1146111,1146115,1146123 CVE References: CVE-2019-14809,CVE-2019-9512,CVE-2019-9514 Sources used: SUSE Linux Enterprise Module for Open Buildservice Development Tools 15-SP1 (src): go1.12-1.12.9-1.15.1 SUSE Linux Enterprise Module for Open Buildservice Development Tools 15 (src): go1.12-1.12.9-1.15.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
openSUSE-SU-2019:2000-1: An update that solves three vulnerabilities and has two fixes is now available. Category: security (important) Bug References: 1139210,1141689,1146111,1146115,1146123 CVE References: CVE-2019-14809,CVE-2019-9512,CVE-2019-9514 Sources used: openSUSE Leap 15.1 (src): go1.12-1.12.9-lp151.2.9.1
openSUSE-SU-2019:2056-1: An update that solves three vulnerabilities and has two fixes is now available. Category: security (moderate) Bug References: 1139210,1141689,1146111,1146115,1146123 CVE References: CVE-2019-14809,CVE-2019-9512,CVE-2019-9514 Sources used: openSUSE Leap 15.1 (src): go1.12-1.12.9-lp151.2.13.1 openSUSE Leap 15.0 (src): go1.12-1.12.9-lp150.8.1
openSUSE-SU-2019:2072-1: An update that solves three vulnerabilities and has one errata is now available. Category: security (moderate) Bug References: 1141688,1146111,1146115,1146123 CVE References: CVE-2019-14809,CVE-2019-9512,CVE-2019-9514 Sources used: openSUSE Leap 15.1 (src): go1.11-1.11.13-lp151.2.9.1 openSUSE Leap 15.0 (src): go1.11-1.11.13-lp150.18.1
openSUSE-SU-2019:2085-1: An update that solves three vulnerabilities and has two fixes is now available. Category: security (moderate) Bug References: 1139210,1141689,1146111,1146115,1146123 CVE References: CVE-2019-14809,CVE-2019-9512,CVE-2019-9514 Sources used: openSUSE Leap 15.1 (src): go1.12-1.12.9-lp151.2.17.1
openSUSE-SU-2019:2130-1: An update that solves three vulnerabilities and has two fixes is now available. Category: security (moderate) Bug References: 1139210,1141689,1146111,1146115,1146123 CVE References: CVE-2019-14809,CVE-2019-9512,CVE-2019-9514 Sources used: openSUSE Leap 15.1 (src): go1.12-1.12.9-lp151.2.21.1
DOne