Buffer Overflow in centra
High severity
GitHub Reviewed
Published
Sep 30, 2019
to the GitHub Advisory Database
•
Updated Jan 9, 2023
Description
Published to the GitHub Advisory Database
Sep 30, 2019
Reviewed
Jun 16, 2020
Last updated
Jan 9, 2023
Denial of Service
Impact
Affected Centra versions will, when not in stream mode, buffer responses to requests into memory with no size limit. This issue affects anyone requesting content from untrusted sources.
Patches
Version 2.4.0 resolves the issue by limiting the size of buffered response body.
Workarounds
Attempting workarounds isn't recommended. Updating is preferred.
For more information
If you have any questions or comments about this advisory, open an issue in ethanent/centra.
References