Golang Go HTTP header injection vulnerability in CVE-2015-5739)
Golang Go HTTP header injection vulnerability in CVE-2015-5739)
Release date:
Updated on:
Affected Systems:
Golang Go
Description:
Bugtraq id: 76281
CVE (CAN) ID: CVE-2015-5739
Golang Go is an open-source programming language.
Golang Go has the http Request Smuggling vulnerability in the net/HTTP library implementation. Attackers can exploit this vulnerability to inject arbitrary HTTP headers into server responses, attackers can bypass security control, perform cache poisoning, and modify request or response pages.
<* Source: R & #195; & #169; gis Leroy
*>
Suggestion:
Vendor patch:
Golang
------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Https://github.com/golang/go/commit/117ddcb83d7f42d6aa72241240af99ded81118e9
Https://github.com/golang/go/commit/300d9a21583e7cf0149a778a0611e76ff7c6680f
Https://github.com/golang/go/commit/143822585e32449860e624cace9d2e521deee62e
This article permanently updates the link address: