An integer overflow vulnerability exists with the length of websocket frames received via a websocket connection. An attacker would use this flaw to cause a denial of service attack on an HTTP Server allowing websocket connections.
| Software | From | Fixed in |
|---|---|---|
| gorillatoolkit / websocket | - | 1.4.1 |
| debian / debian_linux | 9.0 | 9.0.x |
github.com/gorilla/websocket
|
- | 1.4.1 |