Alerts This Week
Warning Icon 1 727
Alerts This Week
Warning Icon 1 727

Mageia 9 2024-0261 Moderate: Golang HTTP Client DoS Threat

mageia
Calendar Grey July 11, 2024
Dist Mageia Esm H88
Recent updates to Go packages bolster security measures in Mageia 9, improving overall performance and network management.
The net/http HTTP/1.1 client mishandled the case where a server responds to a request with an "Expect: 100-continue" header with a non-informational (200 or higher) status

Summary

The net/http HTTP/1.1 client mishandled the case where a server responds to a request with an "Expect: 100-continue" header with a non-informational (200 or higher) status. This mishandling could leave a client connection in an invalid state, where the next request sent on the connection will fail. An attacker sending a request to a net/http/httputil.ReverseProxy proxy can exploit this mishandling to cause a denial of service by sending "Expect: 100-continue" requests which elicit a non-informational response from the backend. Each such request leaves the proxy with an invalid connection, and causes one subsequent request using that connection to fail. (CVE-2024-24791)

References

- https://bugs.mageia.org/show_bug.cgi?id=33380

- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/2Q7H2ERJVZKVOCEC3V4NLCNG24ALF4NI/

- https://www.cve.org/CVERecord?id=CVE-2024-24791

Resolution

SRPMS

- 9/core/golang-1.21.12-1.mga9

Publication date: 11 Jul 2024
URL: https://advisories.mageia.org/MGASA-2024-0261.html
Type: security
CVE: CVE-2024-24791

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here