7.5 High
CVSS3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
0.002 Low
EPSS
Percentile
59.8%
HTTP and MIME header parsing can allocate large amounts of memory, even
when parsing small inputs, potentially leading to a denial of service.
Certain unusual patterns of input data can cause the common function used
to parse HTTP and MIME headers to allocate substantially more memory than
required to hold the parsed headers. An attacker can exploit this behavior
to cause an HTTP server to allocate large amounts of memory from a small
request, potentially leading to memory exhaustion and a denial of service.
With fix, header parsing now correctly allocates only the memory required
to hold parsed headers.
OS | Version | Architecture | Package | Version | Filename |
---|---|---|---|---|---|
ubuntu | 18.04 | noarch | golang-1.10 | <ย any | UNKNOWN |
ubuntu | 14.04 | noarch | golang-1.10 | <ย any | UNKNOWN |
ubuntu | 16.04 | noarch | golang-1.10 | <ย any | UNKNOWN |
ubuntu | 18.04 | noarch | golang-1.13 | <ย 1.13.8-1ubuntu1~18.04.4+esm1 | UNKNOWN |
ubuntu | 20.04 | noarch | golang-1.13 | <ย 1.13.8-1ubuntu1.2 | UNKNOWN |
ubuntu | 22.04 | noarch | golang-1.13 | <ย 1.13.8-1ubuntu2.22.04.2 | UNKNOWN |
ubuntu | 16.04 | noarch | golang-1.13 | <ย 1.13.8-1ubuntu1~16.04.3+esm3 | UNKNOWN |
ubuntu | 20.04 | noarch | golang-1.14 | <ย any | UNKNOWN |
ubuntu | 18.04 | noarch | golang-1.16 | <ย 1.16.2-0ubuntu1~18.04.2+esm1 | UNKNOWN |
ubuntu | 20.04 | noarch | golang-1.16 | <ย 1.16.2-0ubuntu1~20.04.1 | UNKNOWN |
github.com/golang/go/commit/3991f6c41c7dfd167e889234c0cf1d840475e93c (go1.20.3)
github.com/golang/go/commit/d6759e7a059f4208f07aa781402841d7ddaaef96 (go1.19.8)
go.dev/issue/58975
groups.google.com/g/golang-announce/c/Xdv6JL9ENs8
launchpad.net/bugs/cve/CVE-2023-24534
nvd.nist.gov/vuln/detail/CVE-2023-24534
security-tracker.debian.org/tracker/CVE-2023-24534
ubuntu.com/security/notices/USN-6038-1
ubuntu.com/security/notices/USN-6038-2
ubuntu.com/security/notices/USN-6140-1
www.cve.org/CVERecord?id=CVE-2023-24534