The net/http package's Request.ParseMultipartForm method starts writing to temporary files once the request body size surpasses the given "maxMemory" limit. It was possible for an attacker to generate a multipart request crafted such that the server ran out of file descriptors.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2017-10-04T01:00:00Z
Updated: 2024-09-16T22:19:55.128Z
Reserved: 2017-10-03T00:00:00Z
Link: CVE-2017-1000098
Vulnrichment
No data.
NVD
Status : Modified
Published: 2017-10-05T01:29:03.977
Modified: 2024-11-21T03:04:09.340
Link: CVE-2017-1000098
Redhat