First published: Wed Oct 04 2017(Updated: )
The net/http package's Request.ParseMultipartForm method starts writing to temporary files once the request body size surpasses the given "maxMemory" limit. It was possible for an attacker to generate a multipart request crafted such that the server ran out of file descriptors.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Go (Golang) language by Google | <1.6.4 | |
Go (Golang) language by Google | >=1.7<1.7.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.