CVE-2017-1000098

CVE-2017-1000098

The net/http package’s Request.ParseMultipartForm method starts writing to temporary files once the request body size surpasses the given "maxMemory" limit. It was possible for an attacker to generate a multipart request crafted such that the server ran out of file descriptors.

Source: CVE-2017-1000098

답글 남기기

이메일 주소는 공개되지 않습니다. 필수 필드는 *로 표시됩니다