Описание
net/http in Go before 1.15.12 and 1.16.x before 1.16.4 allows remote attackers to cause a denial of service (panic) via a large header to ReadRequest or ReadResponse. Server, Transport, and Client can each be affected in some configurations.
Пакеты
Пакет | Статус | Версия исправления | Релиз | Тип |
---|---|---|---|---|
golang-1.16 | fixed | 1.16.4-1 | package | |
golang-1.15 | fixed | 1.15.9-2 | package | |
golang-1.11 | removed | package | ||
golang-1.11 | postponed | buster | package | |
golang-1.8 | removed | package | ||
golang-1.8 | postponed | stretch | package | |
golang-1.7 | removed | package | ||
golang-1.7 | postponed | stretch | package | |
golang-golang-x-net | fixed | 1:0.0+git20210119.5f4716e+dfsg-3 | package | |
golang-golang-x-net-dev | removed | package | ||
golang-golang-x-net-dev | postponed | buster | package | |
golang-golang-x-net-dev | no-dsa | stretch | package |
Примечания
https://github.com/golang/go/issues/45710
https://github.com/golang/go/issues/45711 (1.15 backport)
https://github.com/golang/go/issues/45712 (1.16 backport)
https://go-review.googlesource.com/c/net/+/313069
golang: introduced by https://github.com/golang/go/commit/ae080c1aecb129a3230e7afecdb4a16ad3da9b3c (go1.5beta1)
golang-golang-x-net: introduced by https://github.com/golang/net/commit/5916dcb167ed985a5b9e6871fbfd74848a4c170b
Связанные уязвимости
net/http in Go before 1.15.12 and 1.16.x before 1.16.4 allows remote attackers to cause a denial of service (panic) via a large header to ReadRequest or ReadResponse. Server, Transport, and Client can each be affected in some configurations.
net/http in Go before 1.15.12 and 1.16.x before 1.16.4 allows remote attackers to cause a denial of service (panic) via a large header to ReadRequest or ReadResponse. Server, Transport, and Client can each be affected in some configurations.
net/http in Go before 1.15.12 and 1.16.x before 1.16.4 allows remote attackers to cause a denial of service (panic) via a large header to ReadRequest or ReadResponse. Server, Transport, and Client can each be affected in some configurations.