Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2020-27813

Опубликовано: 02 дек. 2020
Источник: debian

Описание

An integer overflow vulnerability exists with the length of websocket frames received via a websocket connection. An attacker would use this flaw to cause a denial of service attack on an HTTP Server allowing websocket connections.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
golang-github-gorilla-websocketnot-affectedpackage
golang-websocketremovedpackage

Примечания

  • https://github.com/gorilla/websocket/security/advisories/GHSA-jf24-p9p9-4rjh

  • https://github.com/gorilla/websocket/commit/5b740c29263eb386f33f265561c8262522f19d37 (v1.4.1)

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 5 лет назад

An integer overflow vulnerability exists with the length of websocket frames received via a websocket connection. An attacker would use this flaw to cause a denial of service attack on an HTTP Server allowing websocket connections.

CVSS3: 7.5
redhat
больше 6 лет назад

An integer overflow vulnerability exists with the length of websocket frames received via a websocket connection. An attacker would use this flaw to cause a denial of service attack on an HTTP Server allowing websocket connections.

CVSS3: 7.5
nvd
около 5 лет назад

An integer overflow vulnerability exists with the length of websocket frames received via a websocket connection. An attacker would use this flaw to cause a denial of service attack on an HTTP Server allowing websocket connections.

CVSS3: 7.5
github
больше 4 лет назад

Integer overflow in github.com/gorilla/websocket