1"use strict";(self.webpackChunkspectro_cloud_docs=self.webpackChunkspectro_cloud_docs||[]).push([["11126"],{699099:function(e,t,i){i.r(t),i.d(t,{frontMatter:()=>l,toc:()=>c,default:()=>u,metadata:()=>n,assets:()=>o,contentTitle:()=>a});var n=JSON.parse('{"id":"security-bulletins/reports/pc-cve-2023-24534","title":"CVE-2023-24534","description":"Lifecycle of CVE-2023-24534","source":"@site/docs/docs-content/security-bulletins/reports/pc-cve-2023-24534.md","sourceDirName":"security-bulletins/reports","slug":"/security-bulletins/reports/pc-cve-2023-24534","permalink":"/security-bulletins/reports/pc-cve-2023-24534","draft":false,"unlisted":false,"editUrl":"https://github.com/spectrocloud/librarium/blob/master/docs/docs-content/security-bulletins/reports/pc-cve-2023-24534.md","tags":[{"inline":true,"label":"security","permalink":"/tags/security"},{"inline":true,"label":"cve","permalink":"/tags/cve"}],"version":"current","lastUpdatedAt":null,"frontMatter":{"sidebar_label":"CVE-2023-24534","title":"CVE-2023-24534","description":"Lifecycle of CVE-2023-24534","sidebar_class_name":"hide-from-sidebar","hide_table_of_contents":false,"toc_max_heading_level":2,"tags":["security","cve"]},"sidebar":"docSidebar","previous":{"title":"CVE-2023-0767","permalink":"/security-bulletins/reports/pc-cve-2023-0767"},"next":{"title":"CVE-2023-24536","permalink":"/security-bulletins/reports/pc-cve-2023-24536"}}'),s=i(474848),r=i(884429);let l={sidebar_label:"CVE-2023-24534",title:"CVE-2023-24534",description:"Lifecycle of CVE-2023-24534",sidebar_class_name:"hide-from-sidebar",hide_table_of_contents:!1,toc_max_heading_level:2,tags:["security","cve"]},a,o={},c=[{value:"CVE Details",id:"cve-details",level:2},{value:"Initial Publication",id:"initial-publication",level:2},{value:"Last Update",id:"last-update",level:2},{value:"Third Party Dependency",id:"third-party-dependency",level:2},{value:"NIST CVE Summary",id:"nist-cve-summary",level:2},{value:"CVE Severity",id:"cve-severity",level:2},{value:"Our Official Summary",id:"our-official-summary",level:2},{value:"Status",id:"status",level:2},{value:"Affected Products & Versions",id:"affected-products--versions",level:2},{value:"Revision History",id:"revision-history",level:2}];function d(e){let t={a:"a",h2:"h2",p:"p",...(0,r.R)(),...e.components};return(0,s.jsxs)(s.Fragment,{children:[(0,s.jsx)(t.h2,{id:"cve-details",children:"CVE Details"}),"\n",(0,s.jsxs)(t.p,{children:["Visit the official vulnerability details page for ",(0,s.jsx)(t.a,{href:"https://nvd.nist.gov/vuln/detail/cve-2023-24534",children:"CVE-2023-24534"})," to learn more."]}),"\n",(0,s.jsx)(t.h2,{id:"initial-publication",children:"Initial Publication"}),"\n",(0,s.jsx)(t.p,{children:"10/25/2024"}),"\n",(0,s.jsx)(t.h2,{id:"last-update",children:"Last Update"}),"\n",(0,s.jsx)(t.p,{children:"10/10/2025"}),"\n",(0,s.jsx)(t.h2,{id:"third-party-dependency",children:"Third Party Dependency"}),"\n",(0,s.jsx)(t.p,{children:"go"}),"\n",(0,s.jsx)(t.h2,{id:"nist-cve-summary",children:"NIST CVE Summary"}),"\n",(0,s.jsx)(t.p,{children:"HTTP and MIME header parsing can allocate large amounts of memory, even when parsing small inputs, potentially leading to a denial of service. Certain unusual patterns of input data can cause the common function used to parse HTTP and MIME headers to allocate substantially more memory than required to hold the parsed headers. An attacker can exploit this behavior to cause an HTTP server to allocate large amounts of memory from a small request, potentially leading to memory exhaustion and a denial of service. With fix, header parsing now correctly allocates only the memory required to hold parsed headers."}),"\n",(0,s.jsx)(t.h2,{id:"cve-severity",children:"CVE Severity"}),"\n",(0,s.jsx)(t.p,{children:(0,s.jsx)(t.a,{href:"https://nvd.nist.gov/vuln/detail/cve-2023-24534",children:"7.5"})}),"\n",(0,s.jsx)(t.h2,{id:"our-official-summary",children:"Our Official Summary"}),"\n",(0,s.jsx)(t.p,{children:"This vulnerability is a false positive. Although this is reported by the scanning tools on some of the components, further checks indicate the symbol/function with the vulnerability while present is not being used."}),"\n",(0,s.jsx)(t.h2,{id:"status",children:"Status"}),"\n",(0,s.jsx)(t.p,{children:"Ongoing"}),"\n",(0,s.jsx)(t.h2,{id:"affected-products--versions",children:"Affected Products & Versions"}),"\n",(0,s.jsx)(t.p,{children:"This CVE is non-impacting as the impacting symbol and/or function is not used in the product"}),"\n",(0,s.jsx)(t.h2,{id:"revision-history",children:"Revision History"}),"\n",(0,s.jsx)(t.p,{children:"No revisions available."})]})}function u(e={}){let{wrapper:t}={...(0,r.R)(),...e.components};return t?(0,s.jsx)(t,{...e,children:(0,s.jsx)(d,{...e})}):d(e)}},884429:function(e,t,i){i.d(t,{R:()=>l,x:()=>a});var n=i(296540);let s={},r=n.createContext(s);function l(e){let t=n.useContext(r);return n.useMemo(function(){return"function"==typeof e?e(t):{...t,...e}},[t,e])}function a(e){let t;return t=e.disableParentContext?"function"==typeof e.components?e.components(s):e.components||s:l(e.components),n.createElement(r.Provider,{value:t},e.children)}}}]);
Line numbers count LF bytes from the start of the resource, as the search results do. Vendor segments are library code the classifier recognised; they are stored but not indexed. Bytes are shown as Latin1 characters, one per byte.