Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2017-1000098

Опубликовано: 05 окт. 2017
Источник: debian
EPSS Низкий

Описание

The net/http package's Request.ParseMultipartForm method starts writing to temporary files once the request body size surpasses the given "maxMemory" limit. It was possible for an attacker to generate a multipart request crafted such that the server ran out of file descriptors.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
golang-1.9not-affectedpackage
golang-1.8not-affectedpackage
golang-1.7fixed1.7.4-1package
golangremovedpackage
golangignoredjessiepackage

Примечания

  • https://groups.google.com/forum/#!msg/golang-dev/4NdLzS8sls8/uIz8QlnIBQAJ

  • https://golang.org/cl/30410

  • https://golang.org/issue/17965

EPSS

Процентиль: 62%
0.00434
Низкий

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 8 лет назад

The net/http package's Request.ParseMultipartForm method starts writing to temporary files once the request body size surpasses the given "maxMemory" limit. It was possible for an attacker to generate a multipart request crafted such that the server ran out of file descriptors.

CVSS3: 5.9
redhat
около 9 лет назад

The net/http package's Request.ParseMultipartForm method starts writing to temporary files once the request body size surpasses the given "maxMemory" limit. It was possible for an attacker to generate a multipart request crafted such that the server ran out of file descriptors.

CVSS3: 7.5
nvd
больше 8 лет назад

The net/http package's Request.ParseMultipartForm method starts writing to temporary files once the request body size surpasses the given "maxMemory" limit. It was possible for an attacker to generate a multipart request crafted such that the server ran out of file descriptors.

CVSS3: 7.5
github
больше 3 лет назад

The net/http package's Request.ParseMultipartForm method starts writing to temporary files once the request body size surpasses the given "maxMemory" limit. It was possible for an attacker to generate a multipart request crafted such that the server ran out of file descriptors.

EPSS

Процентиль: 62%
0.00434
Низкий