Описание
ELSA-2023-5837: nghttp2 security update (IMPORTANT)
[1.33.0-5]
- fix HTTP/2 Rapid Reset (CVE-2023-44487)
[1.33.0-4]
- prevent DoS caused by overly large SETTINGS frames (CVE-2020-11080)
Обновленные пакеты
Oracle Linux 8
Oracle Linux aarch64
libnghttp2
1.33.0-5.el8_8
libnghttp2-devel
1.33.0-5.el8_8
nghttp2
1.33.0-5.el8_8
Oracle Linux x86_64
libnghttp2
1.33.0-5.el8_8
libnghttp2-devel
1.33.0-5.el8_8
nghttp2
1.33.0-5.el8_8
Связанные CVE
Связанные уязвимости
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
The HTTP/2 protocol allows a denial of service (server resource consum ...