CVE-2017-1000098
05.10.2017, 01:29
The net/http package's Request.ParseMultipartForm method starts writing to temporary files once the request body size surpasses the given "maxMemory" limit. It was possible for an attacker to generate a multipart request crafted such that the server ran out of file descriptors.Enginsight
Vendor | Product | Version |
---|---|---|
golang | go | 𝑥 < 1.6.4 |
golang | go | 1.7 ≤ 𝑥 < 1.7.4 |
𝑥
= Vulnerable software versions

Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
golang |
| ||||||||||||||||||||||||||||||||||
golang-1.6 |
| ||||||||||||||||||||||||||||||||||
golang-1.7 |
| ||||||||||||||||||||||||||||||||||
golang-1.8 |
| ||||||||||||||||||||||||||||||||||
golang-1.9 |
|
Common Weakness Enumeration