Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2022-41723

Опубликовано: 28 фев. 2023
Источник: debian
EPSS Низкий

Описание

A maliciously crafted HTTP/2 stream could cause excessive CPU consumption in the HPACK decoder, sufficient to cause a denial of service from a small number of small requests.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
golang-1.20fixed1.20.1-1package
golang-1.19fixed1.19.6-1experimentalpackage
golang-1.19fixed1.19.6-2package
golang-1.15removedpackage
golang-1.15no-dsabullseyepackage
golang-1.11removedpackage
golang-1.11postponedbusterpackage
golang-golang-x-netfixed1:0.7.0+dfsg-1package
golang-golang-x-netno-dsabullseyepackage

Примечания

  • https://groups.google.com/g/golang-announce/c/V0aBFqaFs_E

  • https://go.dev/issue/57855

EPSS

Процентиль: 46%
0.00229
Низкий

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 2 лет назад

A maliciously crafted HTTP/2 stream could cause excessive CPU consumption in the HPACK decoder, sufficient to cause a denial of service from a small number of small requests.

CVSS3: 7.5
redhat
больше 2 лет назад

A maliciously crafted HTTP/2 stream could cause excessive CPU consumption in the HPACK decoder, sufficient to cause a denial of service from a small number of small requests.

CVSS3: 7.5
nvd
больше 2 лет назад

A maliciously crafted HTTP/2 stream could cause excessive CPU consumption in the HPACK decoder, sufficient to cause a denial of service from a small number of small requests.

CVSS3: 7.5
msrc
4 месяца назад

Описание отсутствует

CVSS3: 7.5
redos
больше 1 года назад

Уязвимость podman

EPSS

Процентиль: 46%
0.00229
Низкий