Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2021:0932-1

Опубликовано: 24 мар. 2021
Источник: suse-cvrf

Описание

Security update for nghttp2

This update for nghttp2 fixes the following issues:

Security issues fixed:

  • CVE-2020-11080: HTTP/2 Large Settings Frame DoS (bsc#1181358).
  • CVE-2019-9513: Fixed HTTP/2 implementation that is vulnerable to resource loops, potentially leading to a denial of service (bsc#1146184).
  • CVE-2019-9511: Fixed HTTP/2 implementations that are vulnerable to window size manipulation and stream prioritization manipulation, potentially leading to a denial of service (bsc#1146182).
  • CVE-2018-1000168: Fixed ALTSVC frame client side denial of service (bsc#1088639).
  • CVE-2016-1544: Fixed out of memory due to unlimited incoming HTTP header fields (bsc#966514).

Bug fixes and enhancements:

  • Packages must not mark license files as %doc (bsc#1082318)
  • Typo in description of libnghttp2_asio1 (bsc#962914)
  • Fixed mistake in spec file (bsc#1125689)
  • Fixed build issue with boost 1.70.0 (bsc#1134616)
  • Fixed build issue with GCC 6 (bsc#964140)
  • Feature: Add W&S module (FATE#326776, bsc#1112438)

Список пакетов

Container suse/ltss/sle12.5/sles12sp5:latest
libnghttp2-14-1.39.2-3.5.1
Container suse/sles12sp4:latest
libnghttp2-14-1.39.2-3.5.1
Container suse/sles12sp5:latest
libnghttp2-14-1.39.2-3.5.1
HPE Helion OpenStack 8
libnghttp2-14-1.39.2-3.5.1
Image SLES12-SP4-Azure-BYOS
libnghttp2-14-1.39.2-3.5.1
Image SLES12-SP4-EC2-HVM-BYOS
libnghttp2-14-1.39.2-3.5.1
Image SLES12-SP4-GCE-BYOS
libnghttp2-14-1.39.2-3.5.1
Image SLES12-SP4-SAP-Azure
libnghttp2-14-1.39.2-3.5.1
Image SLES12-SP4-SAP-Azure-BYOS
libnghttp2-14-1.39.2-3.5.1
Image SLES12-SP4-SAP-Azure-LI-BYOS-Production
libnghttp2-14-1.39.2-3.5.1
Image SLES12-SP4-SAP-Azure-VLI-BYOS-Production
libnghttp2-14-1.39.2-3.5.1
Image SLES12-SP4-SAP-EC2-HVM
libnghttp2-14-1.39.2-3.5.1
Image SLES12-SP4-SAP-EC2-HVM-BYOS
libnghttp2-14-1.39.2-3.5.1
Image SLES12-SP4-SAP-GCE
libnghttp2-14-1.39.2-3.5.1
Image SLES12-SP4-SAP-GCE-BYOS
libnghttp2-14-1.39.2-3.5.1
Image SLES12-SP5-Azure-BYOS
libnghttp2-14-1.39.2-3.5.1
Image SLES12-SP5-Azure-Basic-On-Demand
libnghttp2-14-1.39.2-3.5.1
Image SLES12-SP5-Azure-HPC-BYOS
libnghttp2-14-1.39.2-3.5.1
Image SLES12-SP5-Azure-HPC-On-Demand
libnghttp2-14-1.39.2-3.5.1
Image SLES12-SP5-Azure-SAP-BYOS
libnghttp2-14-1.39.2-3.5.1
Image SLES12-SP5-Azure-SAP-On-Demand
libnghttp2-14-1.39.2-3.5.1
Image SLES12-SP5-Azure-Standard-On-Demand
libnghttp2-14-1.39.2-3.5.1
Image SLES12-SP5-EC2-BYOS
libnghttp2-14-1.39.2-3.5.1
Image SLES12-SP5-EC2-ECS-On-Demand
libnghttp2-14-1.39.2-3.5.1
Image SLES12-SP5-EC2-On-Demand
libnghttp2-14-1.39.2-3.5.1
Image SLES12-SP5-EC2-SAP-BYOS
libnghttp2-14-1.39.2-3.5.1
Image SLES12-SP5-EC2-SAP-On-Demand
libnghttp2-14-1.39.2-3.5.1
Image SLES12-SP5-GCE-BYOS
libnghttp2-14-1.39.2-3.5.1
Image SLES12-SP5-GCE-On-Demand
libnghttp2-14-1.39.2-3.5.1
Image SLES12-SP5-GCE-SAP-BYOS
libnghttp2-14-1.39.2-3.5.1
Image SLES12-SP5-GCE-SAP-On-Demand
libnghttp2-14-1.39.2-3.5.1
Image SLES12-SP5-OCI-BYOS-BYOS
libnghttp2-14-1.39.2-3.5.1
Image SLES12-SP5-OCI-BYOS-SAP-BYOS
libnghttp2-14-1.39.2-3.5.1
Image SLES12-SP5-SAP-Azure-LI-BYOS-Production
libnghttp2-14-1.39.2-3.5.1
Image SLES12-SP5-SAP-Azure-VLI-BYOS-Production
libnghttp2-14-1.39.2-3.5.1
SUSE Linux Enterprise Server 12 SP2-BCL
libnghttp2-14-1.39.2-3.5.1
SUSE Linux Enterprise Server 12 SP2-LTSS
libnghttp2-14-1.39.2-3.5.1
SUSE Linux Enterprise Server 12 SP3-BCL
libnghttp2-14-1.39.2-3.5.1
SUSE Linux Enterprise Server 12 SP3-LTSS
libnghttp2-14-1.39.2-3.5.1
SUSE Linux Enterprise Server 12 SP4-LTSS
libnghttp2-14-1.39.2-3.5.1
libnghttp2-14-32bit-1.39.2-3.5.1
SUSE Linux Enterprise Server 12 SP5
libnghttp2-14-1.39.2-3.5.1
libnghttp2-14-32bit-1.39.2-3.5.1
SUSE Linux Enterprise Server for SAP Applications 12 SP2
libnghttp2-14-1.39.2-3.5.1
SUSE Linux Enterprise Server for SAP Applications 12 SP3
libnghttp2-14-1.39.2-3.5.1
SUSE Linux Enterprise Server for SAP Applications 12 SP4
libnghttp2-14-1.39.2-3.5.1
libnghttp2-14-32bit-1.39.2-3.5.1
SUSE Linux Enterprise Server for SAP Applications 12 SP5
libnghttp2-14-1.39.2-3.5.1
libnghttp2-14-32bit-1.39.2-3.5.1
SUSE OpenStack Cloud 7
libnghttp2-14-1.39.2-3.5.1
SUSE OpenStack Cloud 8
libnghttp2-14-1.39.2-3.5.1
SUSE OpenStack Cloud 9
libnghttp2-14-1.39.2-3.5.1
libnghttp2-14-32bit-1.39.2-3.5.1
SUSE OpenStack Cloud Crowbar 8
libnghttp2-14-1.39.2-3.5.1
SUSE OpenStack Cloud Crowbar 9
libnghttp2-14-1.39.2-3.5.1
libnghttp2-14-32bit-1.39.2-3.5.1

Описание

nghttp2 before 1.7.1 allows remote attackers to cause a denial of service (memory exhaustion).


Затронутые продукты
Container suse/ltss/sle12.5/sles12sp5:latest:libnghttp2-14-1.39.2-3.5.1
Container suse/sles12sp4:latest:libnghttp2-14-1.39.2-3.5.1
Container suse/sles12sp5:latest:libnghttp2-14-1.39.2-3.5.1
HPE Helion OpenStack 8:libnghttp2-14-1.39.2-3.5.1

Ссылки

Описание

nghttp2 version >= 1.10.0 and nghttp2 <= v1.31.0 contains an Improper Input Validation CWE-20 vulnerability in ALTSVC frame handling that can result in segmentation fault leading to denial of service. This attack appears to be exploitable via network client. This vulnerability appears to have been fixed in >= 1.31.1.


Затронутые продукты
Container suse/ltss/sle12.5/sles12sp5:latest:libnghttp2-14-1.39.2-3.5.1
Container suse/sles12sp4:latest:libnghttp2-14-1.39.2-3.5.1
Container suse/sles12sp5:latest:libnghttp2-14-1.39.2-3.5.1
HPE Helion OpenStack 8:libnghttp2-14-1.39.2-3.5.1

Ссылки

Описание

Some HTTP/2 implementations are vulnerable to window size manipulation and stream prioritization manipulation, potentially leading to a denial of service. The attacker requests a large amount of data from a specified resource over multiple streams. They manipulate window size and stream priority to force the server to queue the data in 1-byte chunks. Depending on how efficiently this data is queued, this can consume excess CPU, memory, or both.


Затронутые продукты
Container suse/ltss/sle12.5/sles12sp5:latest:libnghttp2-14-1.39.2-3.5.1
Container suse/sles12sp4:latest:libnghttp2-14-1.39.2-3.5.1
Container suse/sles12sp5:latest:libnghttp2-14-1.39.2-3.5.1
HPE Helion OpenStack 8:libnghttp2-14-1.39.2-3.5.1

Ссылки

Описание

Some HTTP/2 implementations are vulnerable to resource loops, potentially leading to a denial of service. The attacker creates multiple request streams and continually shuffles the priority of the streams in a way that causes substantial churn to the priority tree. This can consume excess CPU.


Затронутые продукты
Container suse/ltss/sle12.5/sles12sp5:latest:libnghttp2-14-1.39.2-3.5.1
Container suse/sles12sp4:latest:libnghttp2-14-1.39.2-3.5.1
Container suse/sles12sp5:latest:libnghttp2-14-1.39.2-3.5.1
HPE Helion OpenStack 8:libnghttp2-14-1.39.2-3.5.1

Ссылки

Описание

In nghttp2 before version 1.41.0, the overly large HTTP/2 SETTINGS frame payload causes denial of service. The proof of concept attack involves a malicious client constructing a SETTINGS frame with a length of 14,400 bytes (2400 individual settings entries) over and over again. The attack causes the CPU to spike at 100%. nghttp2 v1.41.0 fixes this vulnerability. There is a workaround to this vulnerability. Implement nghttp2_on_frame_recv_callback callback, and if received frame is SETTINGS frame and the number of settings entries are large (e.g., > 32), then drop the connection.


Затронутые продукты
Container suse/ltss/sle12.5/sles12sp5:latest:libnghttp2-14-1.39.2-3.5.1
Container suse/sles12sp4:latest:libnghttp2-14-1.39.2-3.5.1
Container suse/sles12sp5:latest:libnghttp2-14-1.39.2-3.5.1
HPE Helion OpenStack 8:libnghttp2-14-1.39.2-3.5.1

Ссылки
Уязвимость SUSE-SU-2021:0932-1