CVE-2020-27813
02.12.2020, 01:15
An integer overflow vulnerability exists with the length of websocket frames received via a websocket connection. An attacker would use this flaw to cause a denial of service attack on an HTTP Server allowing websocket connections.Enginsight
| Vendor | Product | Version |
|---|---|---|
| gorillatoolkit | websocket | 𝑥 < 1.4.1 |
| debian | debian_linux | 9.0 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| golang-github-gorilla-websocket |
| ||||||||||||||||||||
| golang-websocket |
|
References