CVE-2017-1000098

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
05/10/2017
Last modified:
20/04/2025

Description

The net/http package's Request.ParseMultipartForm method starts writing to temporary files once the request body size surpasses the given "maxMemory" limit. It was possible for an attacker to generate a multipart request crafted such that the server ran out of file descriptors.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:golang:go:*:*:*:*:*:*:*:* 1.6.4 (excluding)
cpe:2.3:a:golang:go:*:*:*:*:*:*:*:* 1.7 (including) 1.7.4 (excluding)