安全公告/【CVE-2023-24534】

基本信息

漏洞名称:
受影响操作系统:Asianux
危险等级:高危
影响源码包:skopeo
CVSS评分:7.5
发现日期:2023-11-18
修复版本:skopeo-1.1.0-9

漏洞描述

HTTP and MIME header parsing can allocate large amounts of memory, even when parsing small inputs, potentially leading to a denial of service. Certain unusual patterns of input data can cause the common function used to parse HTTP and MIME headers to allocate substantially more memory than required to hold the parsed headers. An attacker can exploit this behavior to cause an HTTP server to allocate large amounts of memory from a small request, potentially leading to memory exhaustion and a denial of service. With fix, header parsing now correctly allocates only the memory required to hold parsed headers.

修复方式

yum update PackageName

漏洞判定

执行命令yum info PackageName获取软件包版本号,版本小于修复版本,则受此漏洞影响,版本大于等于修复版本,则此漏洞已修复

补丁

参考

https://gitee.com/src-openeuler/skopeo/issues/I6T1G8
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24534
https://nvd.nist.gov/vuln/detail/CVE-2023-24534