CVE-2017-1000098 — DEPRECATED: Uncontrolled File Descriptor Consumption in GO
Severity
7.5HIGHNVD
EPSS
0.4%
top 37.13%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedOct 5
Latest updateMay 14
Description
The net/http package's Request.ParseMultipartForm method starts writing to temporary files once the request body size surpasses the given "maxMemory" limit. It was possible for an attacker to generate a multipart request crafted such that the server ran out of file descriptors.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6
Affected Packages1 packages
Patches
🔴Vulnerability Details
4📋Vendor Advisories
1💬Community
3Bugzilla
▶
Bugzilla
▶