Lucene search

K
ubuntucveUbuntu.comUB:CVE-2023-24534
HistoryApr 06, 2023 - 12:00 a.m.

CVE-2023-24534

2023-04-0600:00:00
ubuntu.com
ubuntu.com
9
cve-2023-24534
denial of service
http parsing
mime parsing
memory exhaustion

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

0.002 Low

EPSS

Percentile

59.8%

HTTP and MIME header parsing can allocate large amounts of memory, even
when parsing small inputs, potentially leading to a denial of service.
Certain unusual patterns of input data can cause the common function used
to parse HTTP and MIME headers to allocate substantially more memory than
required to hold the parsed headers. An attacker can exploit this behavior
to cause an HTTP server to allocate large amounts of memory from a small
request, potentially leading to memory exhaustion and a denial of service.
With fix, header parsing now correctly allocates only the memory required
to hold parsed headers.

OSVersionArchitecturePackageVersionFilename
ubuntu18.04noarchgolang-1.10<ย anyUNKNOWN
ubuntu14.04noarchgolang-1.10<ย anyUNKNOWN
ubuntu16.04noarchgolang-1.10<ย anyUNKNOWN
ubuntu18.04noarchgolang-1.13<ย 1.13.8-1ubuntu1~18.04.4+esm1UNKNOWN
ubuntu20.04noarchgolang-1.13<ย 1.13.8-1ubuntu1.2UNKNOWN
ubuntu22.04noarchgolang-1.13<ย 1.13.8-1ubuntu2.22.04.2UNKNOWN
ubuntu16.04noarchgolang-1.13<ย 1.13.8-1ubuntu1~16.04.3+esm3UNKNOWN
ubuntu20.04noarchgolang-1.14<ย anyUNKNOWN
ubuntu18.04noarchgolang-1.16<ย 1.16.2-0ubuntu1~18.04.2+esm1UNKNOWN
ubuntu20.04noarchgolang-1.16<ย 1.16.2-0ubuntu1~20.04.1UNKNOWN
Rows per page:
1-10 of 191

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

0.002 Low

EPSS

Percentile

59.8%