Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

openSUSE-SU-2019:2234-1

Опубликовано: 01 окт. 2019
Источник: suse-cvrf

Описание

Security update for nghttp2

This update for nghttp2 fixes the following issues:

Security issues fixed:

  • CVE-2019-9513: Fixed HTTP/2 implementation that is vulnerable to resource loops, potentially leading to a denial of service (bsc#1146184).
  • CVE-2019-9511: Fixed HTTP/2 implementations that are vulnerable to window size manipulation and stream prioritization manipulation, potentially leading to a denial of service (bsc#11461).

Bug fixes and enhancements:

  • Fixed mistake in spec file (bsc#1125689)
  • Fixed build issue with boost 1.70.0 (bsc#1134616)
  • Feature: Add W&S module (FATE#326776, bsc#1112438)

This update was imported from the SUSE:SLE-15:Update update project.

Список пакетов

openSUSE Leap 15.0
libnghttp2-14-1.39.2-lp150.2.3.1
libnghttp2-14-32bit-1.39.2-lp150.2.3.1
libnghttp2-devel-1.39.2-lp150.2.3.1
libnghttp2_asio-devel-1.39.2-lp150.2.3.1
libnghttp2_asio1-1.39.2-lp150.2.3.1
libnghttp2_asio1-32bit-1.39.2-lp150.2.3.1
nghttp2-1.39.2-lp150.2.3.1
python3-nghttp2-1.39.2-lp150.2.3.1

Описание

Some HTTP/2 implementations are vulnerable to window size manipulation and stream prioritization manipulation, potentially leading to a denial of service. The attacker requests a large amount of data from a specified resource over multiple streams. They manipulate window size and stream priority to force the server to queue the data in 1-byte chunks. Depending on how efficiently this data is queued, this can consume excess CPU, memory, or both.


Затронутые продукты
openSUSE Leap 15.0:libnghttp2-14-1.39.2-lp150.2.3.1
openSUSE Leap 15.0:libnghttp2-14-32bit-1.39.2-lp150.2.3.1
openSUSE Leap 15.0:libnghttp2-devel-1.39.2-lp150.2.3.1
openSUSE Leap 15.0:libnghttp2_asio-devel-1.39.2-lp150.2.3.1

Ссылки

Описание

Some HTTP/2 implementations are vulnerable to resource loops, potentially leading to a denial of service. The attacker creates multiple request streams and continually shuffles the priority of the streams in a way that causes substantial churn to the priority tree. This can consume excess CPU.


Затронутые продукты
openSUSE Leap 15.0:libnghttp2-14-1.39.2-lp150.2.3.1
openSUSE Leap 15.0:libnghttp2-14-32bit-1.39.2-lp150.2.3.1
openSUSE Leap 15.0:libnghttp2-devel-1.39.2-lp150.2.3.1
openSUSE Leap 15.0:libnghttp2_asio-devel-1.39.2-lp150.2.3.1

Ссылки