Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2019-9512

Опубликовано: 13 авг. 2019
Источник: debian

Описание

Some HTTP/2 implementations are vulnerable to ping floods, potentially leading to a denial of service. The attacker sends continual pings to an HTTP/2 peer, causing the peer to build an internal queue of responses. Depending on how efficiently this data is queued, this can consume excess CPU, memory, or both.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
golang-1.13fixed1.13~beta1-3package
golang-1.12fixed1.12.8-1package
golang-1.11fixed1.11.13-1package
golang-1.8removedpackage
golang-1.8ignoredstretchpackage
golang-1.7removedpackage
golang-1.7ignoredstretchpackage
golangremovedpackage
golangnot-affectedjessiepackage
golang-golang-x-net-devfixed1:0.0+git20190811.74dc4d7+dfsg-1package
golang-golang-x-net-devpostponedbusterpackage
trafficserverfixed8.0.5+ds-1package
h2ofixed2.2.5+dfsg2-3package

Примечания

  • Issue: https://github.com/golang/go/issues/33606

  • https://github.com/golang/go/commit/e152b01a468a1c18a290bf9aec52ccea7693c7f2 (golang-1.11)

  • https://github.com/golang/go/commit/7139b45d1410ded14e1e131151fd8dfc435ede6c (golang-1.12)

  • https://github.com/Netflix/security-bulletins/blob/master/advisories/third-party/2019-002.md

  • https://nodejs.org/en/blog/vulnerability/aug-2019-security-releases/

  • https://raw.githubusercontent.com/apache/trafficserver/8.0.x/CHANGELOG-8.0.4

  • https://github.com/h2o/h2o/issues/2090

  • https://github.com/h2o/h2o/commit/743d6b6118c29b75d0b84ef7950a2721c32dfe3f

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 6 лет назад

Some HTTP/2 implementations are vulnerable to ping floods, potentially leading to a denial of service. The attacker sends continual pings to an HTTP/2 peer, causing the peer to build an internal queue of responses. Depending on how efficiently this data is queued, this can consume excess CPU, memory, or both.

CVSS3: 7.5
redhat
почти 6 лет назад

Some HTTP/2 implementations are vulnerable to ping floods, potentially leading to a denial of service. The attacker sends continual pings to an HTTP/2 peer, causing the peer to build an internal queue of responses. Depending on how efficiently this data is queued, this can consume excess CPU, memory, or both.

CVSS3: 7.5
nvd
почти 6 лет назад

Some HTTP/2 implementations are vulnerable to ping floods, potentially leading to a denial of service. The attacker sends continual pings to an HTTP/2 peer, causing the peer to build an internal queue of responses. Depending on how efficiently this data is queued, this can consume excess CPU, memory, or both.

CVSS3: 7.5
msrc
почти 6 лет назад

HTTP/2 Server Denial of Service Vulnerability

CVSS3: 7.5
github
около 3 лет назад

golang.org/x/net/http vulnerable to ping floods