CVE-2017-1000098 PUBLISHED

The net/http package's Request.ParseMultipartForm method starts writing to temporary files once the request body size surpasses the given "maxMemory" limit. It was possible for an attacker to generate a multipart request crafted such that the server ran out of file descriptors.

EPSS 0.43% · 62.6th percentile

Risk Scores

EPSS Score
0.43%
62.6th percentile

Affected Products

VendorProductVersions
Ubuntu:16.04:LTSgolang-1.60, 1.6-0ubuntu1, 1.6-0ubuntu2

Timeline

References

Open in Interactive Console →