Wind River Support Network

Meet the Support Network

Home CVE Database CVE-2023-39326

CVE-2023-39326

Description

A malicious HTTP sender can use chunk extensions to cause a receiver reading from a request or response body to read many more bytes from the network than are in the body. A malicious HTTP client can further exploit this to cause a server to automatically read a large amount of data (up to about 1GiB) when a handler fails to read the entire body of a request. Chunk extensions are a little-used HTTP feature which permit including additional metadata in a request or response body sent using the chunked encoding. The net/http chunked encoding reader discards this metadata. A sender can exploit this by inserting a large metadata segment with each byte transferred. The chunk reader now produces an error if the ratio of real body to encoded bytes grows too small.

Priority: --
CVSS v3: 5.3
Component: go
Publish Date: Nov 30, 2023
Related ID: --
CVSS v2: MEDIUM
Modified Date: Nov 30, 2023

Find out more about CVE-2023-39326 from the MITRE-CVE dictionary and NIST NVD


Products Affected

Login may be required to access defects or downloads.

Product Name Status Defect Fixed Downloads
Linux
Wind River Linux LTS 17 Requires LTSS -- -- --
Wind River Linux 8 Not Vulnerable -- -- --
Wind River Linux 9 Requires LTSS -- -- --
Wind River Linux 7 Not Vulnerable -- -- --
Wind River Linux LTS 21 Fixed LIN1021-6891
10.21.20.22 --
Wind River Linux LTS 22 Fixed LIN1022-5942
10.22.33.14 --
Wind River Linux LTS 18 Requires LTSS -- -- --
Wind River Linux LTS 19 Fixed LIN1019-10657
10.19.45.31 --
Wind River Linux CD release N/A -- -- --
Wind River Linux 6 Not Vulnerable -- -- --
Wind River Linux LTS 23 Fixed LIN1023-2818
10.23.30.4 --
VxWorks
VxWorks 7 Not Vulnerable -- -- --
VxWorks 6.9 Not Vulnerable -- -- --
Helix Virtualization Platform Cert Edition
Helix Virtualization Platform Cert Edition Not Vulnerable -- -- --

Related Products

Product Name Status Defect Fixed Downloads

Notes
Requires LTSS - customers must have active LTSS (Long Term Security Shield) Support to receive up-to-date information about vulnerabilities that may affect legacy software. Please contact your Wind River account team or see https://docs.windriver.com/bundle/Support_and_Maintenance_Supplemental_Terms_and_Conditions and https://support2.windriver.com/index.php?page=plc for more information.
Live chat
Online