Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-32wr-c4w3-hg28

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

lib/http2/connection.c in H2O before 1.7.3 and 2.x before 2.0.0-beta5 mishandles HTTP/2 disconnection, which allows remote attackers to cause a denial of service (use-after-free and application crash) or possibly execute arbitrary code via a crafted packet.

lib/http2/connection.c in H2O before 1.7.3 and 2.x before 2.0.0-beta5 mishandles HTTP/2 disconnection, which allows remote attackers to cause a denial of service (use-after-free and application crash) or possibly execute arbitrary code via a crafted packet.

EPSS

Процентиль: 92%
0.07964
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
nvd
больше 9 лет назад

lib/http2/connection.c in H2O before 1.7.3 and 2.x before 2.0.0-beta5 mishandles HTTP/2 disconnection, which allows remote attackers to cause a denial of service (use-after-free and application crash) or possibly execute arbitrary code via a crafted packet.

CVSS3: 7.5
debian
больше 9 лет назад

lib/http2/connection.c in H2O before 1.7.3 and 2.x before 2.0.0-beta5 ...

EPSS

Процентиль: 92%
0.07964
Низкий

7.5 High

CVSS3