Fedora 36 : git-credential-oauth (2023-2663dc67d8)
Discription

The remote Fedora 36 host has a package installed that is affected by a vulnerability as referenced in the FEDORA-2023-2663dc67d8 advisory.

– An attacker can cause excessive memory growth in a Go server accepting HTTP/2 requests. HTTP/2 server connections contain a cache of HTTP header keys sent by the client. While the total number of entries in this cache is capped, an attacker sending very large keys can cause the server to allocate approximately 64 MiB per open connection. (CVE-2022-41717)

Note that Nessus has not tested for this issue but has instead relied only on the application’s self-reported version number.Read More

Back to Main

Subscribe for the latest news: