CVE-2017-1000098
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
05/10/2017
Last modified:
20/04/2025
Description
The net/http package's Request.ParseMultipartForm method starts writing to temporary files once the request body size surpasses the given "maxMemory" limit. It was possible for an attacker to generate a multipart request crafted such that the server ran out of file descriptors.
Impact
Base Score 3.x
7.50
Severity 3.x
HIGH
Base Score 2.0
5.00
Severity 2.0
MEDIUM
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:golang:go:*:*:*:*:*:*:*:* | 1.6.4 (excluding) | |
cpe:2.3:a:golang:go:*:*:*:*:*:*:*:* | 1.7 (including) | 1.7.4 (excluding) |
To consult the complete list of CPE names with products and versions, see this page