{"id":"openSUSE-SU-2016:2536-1","summary":"Security update to go1.4","details":"go1.4 was updated to fix the following vulnerabilities:\n\n- CVE-2016-5386: Remote attacker could have set the application's HTTP_PROXY environment variable via Proxy headers (boo#988487)","modified":"2026-02-04T04:13:41.159690Z","published":"2016-10-14T09:45:15Z","related":["CVE-2016-5386"],"upstream":["CVE-2016-5386"],"references":[{"type":"ADVISORY"},{"type":"REPORT","url":"https://bugzilla.suse.com/988487"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2016-5386"}],"affected":[{"package":{"name":"go1.4","ecosystem":"SUSE:Package Hub 12","purl":"pkg:rpm/suse/go1.4&distro=SUSE%20Package%20Hub%2012"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.4.3-6.1"}]}],"ecosystem_specific":{"binaries":[{"go1.4-doc":"1.4.3-6.1","go1.4":"1.4.3-6.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2016:2536-1.json"}}],"schema_version":"1.7.3"}