Búsqueda de    
Vulnerabilidad   
    Buscar 324607 Descripciones CVE y
145615 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.1.10.2024.0128
Categoría:Mageia Linux Local Security Checks
Título:Mageia: Security Advisory (MGASA-2024-0128)
Resumen:The remote host is missing an update for the 'golang' package(s) announced via the MGASA-2024-0128 advisory.
Descripción:Summary:
The remote host is missing an update for the 'golang' package(s) announced via the MGASA-2024-0128 advisory.

Vulnerability Insight:
CVE-2023-45288: An attacker may cause an HTTP/2 endpoint to read
arbitrary amounts of header data by sending an excessive number of
CONTINUATION frames. Maintaining HPACK state requires parsing and
processing all HEADERS and CONTINUATION frames on a connection. When a
request's headers exceed MaxHeaderBytes, no memory is allocated to store
the excess headers, but they are still parsed. This permits an attacker
to cause an HTTP/2 endpoint to read arbitrary amounts of header data,
all associated with a request which is going to be rejected. These
headers can include Huffman-encoded data which is significantly more
expensive for the receiver to decode than for an attacker to send. The
fix sets a limit on the amount of excess header frames we will process
before closing a connection.

Affected Software/OS:
'golang' package(s) on Mageia 9.

Solution:
Please install the updated package(s).

CVSS Score:
5.0

CVSS Vector:
AV:N/AC:L/Au:N/C:P/I:N/A:N

Referencia Cruzada: Common Vulnerability Exposure (CVE) ID: CVE-2023-45288
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/QRYFHIQ6XRKRYBI2F5UESH67BJBQXUPT/
https://go.dev/cl/576155
https://go.dev/issue/65051
https://groups.google.com/g/golang-announce/c/YgW0sx8mN3M
https://pkg.go.dev/vuln/GO-2024-2687
http://www.openwall.com/lists/oss-security/2024/04/03/16
http://www.openwall.com/lists/oss-security/2024/04/05/4
CopyrightCopyright (C) 2024 Greenbone AG

Esta es sólo una de 145615 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2025 E-Soft Inc. Todos los derechos reservados.