<?xml version="1.0" encoding="UTF-8"?>
<cvrfdoc xmlns:xsd="http://www.w3.org/2001/XMLSchema" xmlns:cpe="http://cpe.mitre.org/language/2.0" xmlns:cvrf="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/cvrf" xmlns:cvrf-common="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/common" xmlns:cvssv2="http://scap.nist.gov/schema/cvss-v2/1.0" xmlns:cvssv3="https://www.first.org/cvss/cvss-v3.0.xsd" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:ns0="http://purl.org/dc/elements/1.1/" xmlns:prod="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/prod" xmlns:scap-core="http://scap.nist.gov/schema/scap-core/1.0" xmlns:sch="http://purl.oclc.org/dsdl/schematron" xmlns:vuln="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/vuln" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/cvrf">
  <DocumentTitle xml:lang="en">Security update for go1.14</DocumentTitle>
  <DocumentType>SUSE Patch</DocumentType>
  <DocumentPublisher Type="Vendor">
    <ContactDetails>security@suse.de</ContactDetails>
    <IssuingAuthority>SUSE Security Team</IssuingAuthority>
  </DocumentPublisher>
  <DocumentTracking>
    <Identification>
      <ID>SUSE-SU-2021:0222-1</ID>
    </Identification>
    <Status>Final</Status>
    <Version>1</Version>
    <RevisionHistory>
      <Revision>
        <Number>1</Number>
        <Date>2021-01-26T14:05:32Z</Date>
        <Description>current</Description>
      </Revision>
    </RevisionHistory>
    <InitialReleaseDate>2021-01-26T14:05:32Z</InitialReleaseDate>
    <CurrentReleaseDate>2021-01-26T14:05:32Z</CurrentReleaseDate>
    <Generator>
      <Engine>cve-database/bin/generate-cvrf.pl</Engine>
      <Date>2017-02-24T01:00:00Z</Date>
    </Generator>
  </DocumentTracking>
  <DocumentNotes>
    <Note Title="Topic" Type="Summary" Ordinal="1" xml:lang="en">Security update for go1.14</Note>
    <Note Title="Details" Type="General" Ordinal="2" xml:lang="en">This update for go1.14 fixes the following issues:

Go was updated to version 1.14.14 (bsc#1164903).

Security issues fixed:

- CVE-2021-3114: Fixed incorrect operations on the P-224 curve in crypto/elliptic (bsc#1181145).
- CVE-2021-3115: Fixed a potential arbitrary code execution in the build process (bsc#1181146).
</Note>
    <Note Title="Terms of Use" Type="Legal Disclaimer" Ordinal="3" xml:lang="en">The CVRF data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).</Note>
    <Note Title="Patchnames" Type="Details" Ordinal="4" xml:lang="en">SUSE-2021-222,SUSE-SLE-Module-Development-Tools-15-SP2-2021-222,SUSE-SLE-Module-Development-Tools-15-SP3-2021-222,SUSE-SLE-Product-HPC-15-SP1-ESPOS-2021-222,SUSE-SLE-Product-HPC-15-SP1-LTSS-2021-222,SUSE-SLE-Product-SLES-15-SP1-BCL-2021-222,SUSE-SLE-Product-SLES-15-SP1-LTSS-2021-222,SUSE-SLE-Product-SLES_SAP-15-SP1-2021-222,SUSE-SLE-Product-SUSE-Manager-Proxy-4.0-2021-222,SUSE-SLE-Product-SUSE-Manager-Retail-Branch-Server-4.0-2021-222,SUSE-SLE-Product-SUSE-Manager-Server-4.0-2021-222,SUSE-Storage-6-2021-222</Note>
  </DocumentNotes>
  <DocumentDistribution xml:lang="en">Copyright SUSE LLC under the Creative Commons License 4.0 with Attribution (CC-BY-4.0)</DocumentDistribution>
  <DocumentReferences>
    <Reference Type="Self">
      <URL>https://www.suse.com/support/update/announcement/2021/suse-su-20210222-1/</URL>
      <Description>Link for SUSE-SU-2021:0222-1</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://lists.suse.com/pipermail/sle-security-updates/2021-January/008248.html</URL>
      <Description>E-Mail link for SUSE-SU-2021:0222-1</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/support/security/rating/</URL>
      <Description>SUSE Security Ratings</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1164903</URL>
      <Description>SUSE Bug 1164903</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1181145</URL>
      <Description>SUSE Bug 1181145</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1181146</URL>
      <Description>SUSE Bug 1181146</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2021-3114/</URL>
      <Description>SUSE CVE CVE-2021-3114 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2021-3115/</URL>
      <Description>SUSE CVE CVE-2021-3115 page</Description>
    </Reference>
  </DocumentReferences>
  <ProductTree xmlns="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/prod">
    <Branch Type="Product Family" Name="SUSE Enterprise Storage 6">
      <Branch Type="Product Name" Name="SUSE Enterprise Storage 6">
        <FullProductName ProductID="SUSE Enterprise Storage 6" CPE="cpe:/o:suse:ses:6">SUSE Enterprise Storage 6</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Linux Enterprise High Performance Computing 15 SP1-ESPOS">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise High Performance Computing 15 SP1-ESPOS">
        <FullProductName ProductID="SUSE Linux Enterprise High Performance Computing 15 SP1-ESPOS" CPE="cpe:/o:suse:sle_hpc-espos:15:sp1">SUSE Linux Enterprise High Performance Computing 15 SP1-ESPOS</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Linux Enterprise High Performance Computing 15 SP1-LTSS">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise High Performance Computing 15 SP1-LTSS">
        <FullProductName ProductID="SUSE Linux Enterprise High Performance Computing 15 SP1-LTSS" CPE="cpe:/o:suse:sle_hpc-ltss:15:sp1">SUSE Linux Enterprise High Performance Computing 15 SP1-LTSS</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Linux Enterprise Module for Development Tools 15 SP2">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Module for Development Tools 15 SP2">
        <FullProductName ProductID="SUSE Linux Enterprise Module for Development Tools 15 SP2" CPE="cpe:/o:suse:sle-module-development-tools:15:sp2">SUSE Linux Enterprise Module for Development Tools 15 SP2</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Linux Enterprise Server 15 SP1-BCL">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Server 15 SP1-BCL">
        <FullProductName ProductID="SUSE Linux Enterprise Server 15 SP1-BCL" CPE="cpe:/o:suse:sles_bcl:15:sp1">SUSE Linux Enterprise Server 15 SP1-BCL</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Linux Enterprise Server 15 SP1-LTSS">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Server 15 SP1-LTSS">
        <FullProductName ProductID="SUSE Linux Enterprise Server 15 SP1-LTSS" CPE="cpe:/o:suse:sles-ltss:15:sp1">SUSE Linux Enterprise Server 15 SP1-LTSS</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Linux Enterprise Server for SAP Applications 15 SP1">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Server for SAP Applications 15 SP1">
        <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 15 SP1" CPE="cpe:/o:suse:sles_sap:15:sp1">SUSE Linux Enterprise Server for SAP Applications 15 SP1</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Manager Proxy 4.0">
      <Branch Type="Product Name" Name="SUSE Manager Proxy 4.0">
        <FullProductName ProductID="SUSE Manager Proxy 4.0" CPE="cpe:/o:suse:suse-manager-proxy:4.0">SUSE Manager Proxy 4.0</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Manager Retail Branch Server 4.0">
      <Branch Type="Product Name" Name="SUSE Manager Retail Branch Server 4.0">
        <FullProductName ProductID="SUSE Manager Retail Branch Server 4.0" CPE="cpe:/o:suse:suse-manager-retail-branch-server:4.0">SUSE Manager Retail Branch Server 4.0</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Manager Server 4.0">
      <Branch Type="Product Name" Name="SUSE Manager Server 4.0">
        <FullProductName ProductID="SUSE Manager Server 4.0" CPE="cpe:/o:suse:suse-manager-server:4.0">SUSE Manager Server 4.0</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Version" Name="go1.14-1.14.14-1.32.1">
      <FullProductName ProductID="go1.14-1.14.14-1.32.1">go1.14-1.14.14-1.32.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="go1.14-doc-1.14.14-1.32.1">
      <FullProductName ProductID="go1.14-doc-1.14.14-1.32.1">go1.14-doc-1.14.14-1.32.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="go1.14-race-1.14.14-1.32.1">
      <FullProductName ProductID="go1.14-race-1.14.14-1.32.1">go1.14-race-1.14.14-1.32.1</FullProductName>
    </Branch>
    <Relationship ProductReference="go1.14-1.14.14-1.32.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Enterprise Storage 6">
      <FullProductName ProductID="SUSE Enterprise Storage 6:go1.14-1.14.14-1.32.1">go1.14-1.14.14-1.32.1 as a component of SUSE Enterprise Storage 6</FullProductName>
    </Relationship>
    <Relationship ProductReference="go1.14-doc-1.14.14-1.32.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Enterprise Storage 6">
      <FullProductName ProductID="SUSE Enterprise Storage 6:go1.14-doc-1.14.14-1.32.1">go1.14-doc-1.14.14-1.32.1 as a component of SUSE Enterprise Storage 6</FullProductName>
    </Relationship>
    <Relationship ProductReference="go1.14-1.14.14-1.32.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise High Performance Computing 15 SP1-ESPOS">
      <FullProductName ProductID="SUSE Linux Enterprise High Performance Computing 15 SP1-ESPOS:go1.14-1.14.14-1.32.1">go1.14-1.14.14-1.32.1 as a component of SUSE Linux Enterprise High Performance Computing 15 SP1-ESPOS</FullProductName>
    </Relationship>
    <Relationship ProductReference="go1.14-doc-1.14.14-1.32.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise High Performance Computing 15 SP1-ESPOS">
      <FullProductName ProductID="SUSE Linux Enterprise High Performance Computing 15 SP1-ESPOS:go1.14-doc-1.14.14-1.32.1">go1.14-doc-1.14.14-1.32.1 as a component of SUSE Linux Enterprise High Performance Computing 15 SP1-ESPOS</FullProductName>
    </Relationship>
    <Relationship ProductReference="go1.14-1.14.14-1.32.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise High Performance Computing 15 SP1-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise High Performance Computing 15 SP1-LTSS:go1.14-1.14.14-1.32.1">go1.14-1.14.14-1.32.1 as a component of SUSE Linux Enterprise High Performance Computing 15 SP1-LTSS</FullProductName>
    </Relationship>
    <Relationship ProductReference="go1.14-doc-1.14.14-1.32.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise High Performance Computing 15 SP1-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise High Performance Computing 15 SP1-LTSS:go1.14-doc-1.14.14-1.32.1">go1.14-doc-1.14.14-1.32.1 as a component of SUSE Linux Enterprise High Performance Computing 15 SP1-LTSS</FullProductName>
    </Relationship>
    <Relationship ProductReference="go1.14-1.14.14-1.32.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Development Tools 15 SP2">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Development Tools 15 SP2:go1.14-1.14.14-1.32.1">go1.14-1.14.14-1.32.1 as a component of SUSE Linux Enterprise Module for Development Tools 15 SP2</FullProductName>
    </Relationship>
    <Relationship ProductReference="go1.14-doc-1.14.14-1.32.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Development Tools 15 SP2">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Development Tools 15 SP2:go1.14-doc-1.14.14-1.32.1">go1.14-doc-1.14.14-1.32.1 as a component of SUSE Linux Enterprise Module for Development Tools 15 SP2</FullProductName>
    </Relationship>
    <Relationship ProductReference="go1.14-1.14.14-1.32.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 15 SP1-BCL">
      <FullProductName ProductID="SUSE Linux Enterprise Server 15 SP1-BCL:go1.14-1.14.14-1.32.1">go1.14-1.14.14-1.32.1 as a component of SUSE Linux Enterprise Server 15 SP1-BCL</FullProductName>
    </Relationship>
    <Relationship ProductReference="go1.14-doc-1.14.14-1.32.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 15 SP1-BCL">
      <FullProductName ProductID="SUSE Linux Enterprise Server 15 SP1-BCL:go1.14-doc-1.14.14-1.32.1">go1.14-doc-1.14.14-1.32.1 as a component of SUSE Linux Enterprise Server 15 SP1-BCL</FullProductName>
    </Relationship>
    <Relationship ProductReference="go1.14-1.14.14-1.32.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 15 SP1-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise Server 15 SP1-LTSS:go1.14-1.14.14-1.32.1">go1.14-1.14.14-1.32.1 as a component of SUSE Linux Enterprise Server 15 SP1-LTSS</FullProductName>
    </Relationship>
    <Relationship ProductReference="go1.14-doc-1.14.14-1.32.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 15 SP1-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise Server 15 SP1-LTSS:go1.14-doc-1.14.14-1.32.1">go1.14-doc-1.14.14-1.32.1 as a component of SUSE Linux Enterprise Server 15 SP1-LTSS</FullProductName>
    </Relationship>
    <Relationship ProductReference="go1.14-1.14.14-1.32.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server for SAP Applications 15 SP1">
      <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 15 SP1:go1.14-1.14.14-1.32.1">go1.14-1.14.14-1.32.1 as a component of SUSE Linux Enterprise Server for SAP Applications 15 SP1</FullProductName>
    </Relationship>
    <Relationship ProductReference="go1.14-doc-1.14.14-1.32.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server for SAP Applications 15 SP1">
      <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 15 SP1:go1.14-doc-1.14.14-1.32.1">go1.14-doc-1.14.14-1.32.1 as a component of SUSE Linux Enterprise Server for SAP Applications 15 SP1</FullProductName>
    </Relationship>
    <Relationship ProductReference="go1.14-1.14.14-1.32.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Manager Proxy 4.0">
      <FullProductName ProductID="SUSE Manager Proxy 4.0:go1.14-1.14.14-1.32.1">go1.14-1.14.14-1.32.1 as a component of SUSE Manager Proxy 4.0</FullProductName>
    </Relationship>
    <Relationship ProductReference="go1.14-doc-1.14.14-1.32.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Manager Proxy 4.0">
      <FullProductName ProductID="SUSE Manager Proxy 4.0:go1.14-doc-1.14.14-1.32.1">go1.14-doc-1.14.14-1.32.1 as a component of SUSE Manager Proxy 4.0</FullProductName>
    </Relationship>
    <Relationship ProductReference="go1.14-1.14.14-1.32.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Manager Retail Branch Server 4.0">
      <FullProductName ProductID="SUSE Manager Retail Branch Server 4.0:go1.14-1.14.14-1.32.1">go1.14-1.14.14-1.32.1 as a component of SUSE Manager Retail Branch Server 4.0</FullProductName>
    </Relationship>
    <Relationship ProductReference="go1.14-doc-1.14.14-1.32.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Manager Retail Branch Server 4.0">
      <FullProductName ProductID="SUSE Manager Retail Branch Server 4.0:go1.14-doc-1.14.14-1.32.1">go1.14-doc-1.14.14-1.32.1 as a component of SUSE Manager Retail Branch Server 4.0</FullProductName>
    </Relationship>
    <Relationship ProductReference="go1.14-1.14.14-1.32.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Manager Server 4.0">
      <FullProductName ProductID="SUSE Manager Server 4.0:go1.14-1.14.14-1.32.1">go1.14-1.14.14-1.32.1 as a component of SUSE Manager Server 4.0</FullProductName>
    </Relationship>
    <Relationship ProductReference="go1.14-doc-1.14.14-1.32.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Manager Server 4.0">
      <FullProductName ProductID="SUSE Manager Server 4.0:go1.14-doc-1.14.14-1.32.1">go1.14-doc-1.14.14-1.32.1 as a component of SUSE Manager Server 4.0</FullProductName>
    </Relationship>
  </ProductTree>
  <vuln:Vulnerability xmlns="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/vuln" Ordinal="1">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">In Go before 1.14.14 and 1.15.x before 1.15.7, crypto/elliptic/p224.go can generate incorrect outputs, related to an underflow of the lowest limb during the final complete reduction in the P-224 field.</Note>
    </Notes>
    <CVE>CVE-2021-3114</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Enterprise Storage 6:go1.14-1.14.14-1.32.1</ProductID>
        <ProductID>SUSE Enterprise Storage 6:go1.14-doc-1.14.14-1.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP1-ESPOS:go1.14-1.14.14-1.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP1-ESPOS:go1.14-doc-1.14.14-1.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP1-LTSS:go1.14-1.14.14-1.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP1-LTSS:go1.14-doc-1.14.14-1.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Development Tools 15 SP2:go1.14-1.14.14-1.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Development Tools 15 SP2:go1.14-doc-1.14.14-1.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP1-BCL:go1.14-1.14.14-1.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP1-BCL:go1.14-doc-1.14.14-1.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP1-LTSS:go1.14-1.14.14-1.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP1-LTSS:go1.14-doc-1.14.14-1.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP1:go1.14-1.14.14-1.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP1:go1.14-doc-1.14.14-1.32.1</ProductID>
        <ProductID>SUSE Manager Proxy 4.0:go1.14-1.14.14-1.32.1</ProductID>
        <ProductID>SUSE Manager Proxy 4.0:go1.14-doc-1.14.14-1.32.1</ProductID>
        <ProductID>SUSE Manager Retail Branch Server 4.0:go1.14-1.14.14-1.32.1</ProductID>
        <ProductID>SUSE Manager Retail Branch Server 4.0:go1.14-doc-1.14.14-1.32.1</ProductID>
        <ProductID>SUSE Manager Server 4.0:go1.14-1.14.14-1.32.1</ProductID>
        <ProductID>SUSE Manager Server 4.0:go1.14-doc-1.14.14-1.32.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSetV2>
        <BaseScoreV2>6.4</BaseScoreV2>
        <VectorV2>AV:N/AC:L/Au:N/C:P/I:P/A:N</VectorV2>
      </ScoreSetV2>
      <ScoreSetV3>
        <BaseScoreV3>4.8</BaseScoreV3>
        <VectorV3>CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N</VectorV3>
      </ScoreSetV3>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2021/suse-su-20210222-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2021-3114.html</URL>
        <Description>CVE-2021-3114</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1181145</URL>
        <Description>SUSE Bug 1181145</Description>
      </Reference>
    </References>
  </vuln:Vulnerability>
  <vuln:Vulnerability xmlns="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/vuln" Ordinal="2">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Go before 1.14.14 and 1.15.x before 1.15.7 on Windows is vulnerable to Command Injection and remote code execution when using the "go get" command to fetch modules that make use of cgo (for example, cgo can execute a gcc program from an untrusted download).</Note>
    </Notes>
    <CVE>CVE-2021-3115</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Enterprise Storage 6:go1.14-1.14.14-1.32.1</ProductID>
        <ProductID>SUSE Enterprise Storage 6:go1.14-doc-1.14.14-1.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP1-ESPOS:go1.14-1.14.14-1.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP1-ESPOS:go1.14-doc-1.14.14-1.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP1-LTSS:go1.14-1.14.14-1.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP1-LTSS:go1.14-doc-1.14.14-1.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Development Tools 15 SP2:go1.14-1.14.14-1.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Development Tools 15 SP2:go1.14-doc-1.14.14-1.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP1-BCL:go1.14-1.14.14-1.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP1-BCL:go1.14-doc-1.14.14-1.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP1-LTSS:go1.14-1.14.14-1.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP1-LTSS:go1.14-doc-1.14.14-1.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP1:go1.14-1.14.14-1.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP1:go1.14-doc-1.14.14-1.32.1</ProductID>
        <ProductID>SUSE Manager Proxy 4.0:go1.14-1.14.14-1.32.1</ProductID>
        <ProductID>SUSE Manager Proxy 4.0:go1.14-doc-1.14.14-1.32.1</ProductID>
        <ProductID>SUSE Manager Retail Branch Server 4.0:go1.14-1.14.14-1.32.1</ProductID>
        <ProductID>SUSE Manager Retail Branch Server 4.0:go1.14-doc-1.14.14-1.32.1</ProductID>
        <ProductID>SUSE Manager Server 4.0:go1.14-1.14.14-1.32.1</ProductID>
        <ProductID>SUSE Manager Server 4.0:go1.14-doc-1.14.14-1.32.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSetV2>
        <BaseScoreV2>5.1</BaseScoreV2>
        <VectorV2>AV:N/AC:H/Au:N/C:P/I:P/A:P</VectorV2>
      </ScoreSetV2>
      <ScoreSetV3>
        <BaseScoreV3>7.3</BaseScoreV3>
        <VectorV3>CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H</VectorV3>
      </ScoreSetV3>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2021/suse-su-20210222-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2021-3115.html</URL>
        <Description>CVE-2021-3115</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1181146</URL>
        <Description>SUSE Bug 1181146</Description>
      </Reference>
    </References>
  </vuln:Vulnerability>
</cvrfdoc>
