Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2018-16844

Опубликовано: 07 нояб. 2018
Источник: ubuntu
Приоритет: medium
EPSS Средний
CVSS2: 7.8
CVSS3: 7.5

Описание

nginx before versions 1.15.6 and 1.14.1 has a vulnerability in the implementation of HTTP/2 that can allow for excessive CPU usage. This issue affects nginx compiled with the ngx_http_v2_module (not compiled by default) if the 'http2' option of the 'listen' directive is used in a configuration file.

РелизСтатусПримечание
bionic

released

1.14.0-0ubuntu1.2
cosmic

released

1.15.5-0ubuntu2.1
devel

released

1.15.6-0ubuntu1
esm-infra-legacy/trusty

not-affected

code not present
esm-infra/bionic

released

1.14.0-0ubuntu1.2
esm-infra/xenial

released

1.10.3-0ubuntu0.16.04.3
precise/esm

DNE

trusty

not-affected

code not present
trusty/esm

not-affected

code not present
upstream

released

1.15.6

Показывать по

EPSS

Процентиль: 93%
0.10883
Средний

7.8 High

CVSS2

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 5.3
redhat
больше 7 лет назад

nginx before versions 1.15.6 and 1.14.1 has a vulnerability in the implementation of HTTP/2 that can allow for excessive CPU usage. This issue affects nginx compiled with the ngx_http_v2_module (not compiled by default) if the 'http2' option of the 'listen' directive is used in a configuration file.

CVSS3: 7.5
nvd
около 7 лет назад

nginx before versions 1.15.6 and 1.14.1 has a vulnerability in the implementation of HTTP/2 that can allow for excessive CPU usage. This issue affects nginx compiled with the ngx_http_v2_module (not compiled by default) if the 'http2' option of the 'listen' directive is used in a configuration file.

CVSS3: 7.5
debian
около 7 лет назад

nginx before versions 1.15.6 and 1.14.1 has a vulnerability in the imp ...

CVSS3: 7.5
github
больше 3 лет назад

nginx before versions 1.15.6 and 1.14.1 has a vulnerability in the implementation of HTTP/2 that can allow for excessive CPU usage. This issue affects nginx compiled with the ngx_http_v2_module (not compiled by default) if the 'http2' option of the 'listen' directive is used in a configuration file.

CVSS3: 7.5
fstec
больше 7 лет назад

Уязвимость реализации протокола HTTP/2 сервера nginx, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 93%
0.10883
Средний

7.8 High

CVSS2

7.5 High

CVSS3