[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248268

 
 

909

 
 

195051

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

ALAS-2015-588 --- golang docker

ID: oval:org.secpod.oval:def:1200073Date: (C)2016-01-04   (M)2022-09-22
Class: PATCHFamily: unix




As discussed upstream -- here and here -- the Go project received notification of an HTTP request smuggling vulnerability in the net/http library. Invalid headers are parsed as valid headers and Double Content-length headers in a request does not generate a 400 error, the second Content-length is ignored.

Platform:
Amazon Linux AMI
Product:
golang
docker
Reference:
ALAS-2015-588
CVE-2015-5741
CVE-2015-5740
CVE-2015-5739
CVE    3
CVE-2015-5739
CVE-2015-5740
CVE-2015-5741
CPE    3
cpe:/o:amazon:linux
cpe:/a:docker:docker
cpe:/a:golang:golang

© SecPod Technologies