7.8

CVE-2019-9515

Some HTTP/2 implementations are vulnerable to a settings flood, potentially leading to a denial of service

Some HTTP/2 implementations are vulnerable to a settings flood, potentially leading to a denial of service. The attacker sends a stream of SETTINGS frames to the peer. Since the RFC requires that the peer reply with one acknowledgement per SETTINGS frame, an empty SETTINGS frame is almost equivalent in behavior to a ping. Depending on how efficiently this data is queued, this can consume excess CPU, memory, or both.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Apple ≫ Swiftnio Version >= 1.0.0 <= 1.4.0
   Apple ≫ macOS X Version >= 10.12
   Canonical ≫ Ubuntu Linux Version >= 14.04
Apache ≫ Traffic Server Version >= 6.0.0 <= 6.2.3
Apache ≫ Traffic Server Version >= 7.0.0 <= 7.1.6
Apache ≫ Traffic Server Version >= 8.0.0 <= 8.0.3
Canonical ≫ Ubuntu Linux Version 16.04 SwEdition lts
Canonical ≫ Ubuntu Linux Version 18.04 SwEdition lts
Canonical ≫ Ubuntu Linux Version 19.04
Debian ≫ Debian Linux Version 9.0
Debian ≫ Debian Linux Version 10.0
Synology ≫ Skynas Version -
Synology ≫ Diskstation Manager Version 6.2
Synology ≫ Vs960hd Firmware Version -
   Synology ≫ Vs960hd Version -
Fedoraproject ≫ Fedora Version 29
Fedoraproject ≫ Fedora Version 30
Opensuse ≫ Leap Version 15.0
Opensuse ≫ Leap Version 15.1
Redhat ≫ Jboss Core Services Version 1.0
Redhat ≫ Openshift Service Mesh Version 1.0
Redhat ≫ Openstack Version 14
Redhat ≫ Quay Version 3.0.0
Redhat ≫ Single Sign-on Version 7.3
Redhat ≫ Software Collections Version 1.0
Redhat ≫ Enterprise Linux Version 8.0
Oracle ≫ Graalvm Version 19.2.0 SwEdition enterprise
Mcafee ≫ Web Gateway Version >= 7.7.2.0 < 7.7.2.24
Mcafee ≫ Web Gateway Version >= 7.8.2.0 < 7.8.2.13
Mcafee ≫ Web Gateway Version >= 8.1.0 < 8.2.0
F5 ≫ Big-ip Local Traffic Manager Version >= 11.6.1 < 11.6.5.1
F5 ≫ Big-ip Local Traffic Manager Version >= 12.1.0 < 12.1.5.1
F5 ≫ Big-ip Local Traffic Manager Version >= 13.1.0 < 13.1.3.2
F5 ≫ Big-ip Local Traffic Manager Version >= 14.0.0 < 14.0.1.1
F5 ≫ Big-ip Local Traffic Manager Version >= 14.1.0 < 14.1.2.1
F5 ≫ Big-ip Local Traffic Manager Version >= 15.0.0 < 15.0.1.1
Nodejs ≫ Node.Js SwEdition - Version >= 8.0.0 <= 8.8.1
Nodejs ≫ Node.Js SwEdition lts Version >= 8.9.0 < 8.16.1
Nodejs ≫ Node.Js SwEdition - Version >= 10.0.0 <= 10.12.0
Nodejs ≫ Node.Js SwEdition lts Version >= 10.13.0 < 10.16.3
Nodejs ≫ Node.Js SwEdition - Version >= 12.0.0 < 12.8.1
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 87.4% 0.997
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
NIST 7.8 10 6.9
AV:N/AC:L/Au:N/C:N/I:N/A:C
CERT.org 7.5 3.9 3.6
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CWE-400 Uncontrolled Resource Consumption

The product does not properly control the allocation and maintenance of a limited resource.

CWE-770 Allocation of Resources Without Limits or Throttling

The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.

https://access.redhat.com/errata/RHSA-2019:3892
Third Party Advisory
https://access.redhat.com/errata/RHSA-2020:0727
Third Party Advisory
https://access.redhat.com/errata/RHSA-2019:4352
Third Party Advisory
https://usn.ubuntu.com/4308-1/
Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00031.html
Third Party Advisory
Mailing List
http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00032.html
Third Party Advisory
Mailing List
https://access.redhat.com/errata/RHSA-2019:2925
Third Party Advisory
https://access.redhat.com/errata/RHSA-2019:2939
Third Party Advisory
https://access.redhat.com/errata/RHSA-2019:2955
Third Party Advisory
https://access.redhat.com/errata/RHSA-2019:4018
Third Party Advisory
https://access.redhat.com/errata/RHSA-2019:4019
Third Party Advisory
https://access.redhat.com/errata/RHSA-2019:4020
Third Party Advisory
https://access.redhat.com/errata/RHSA-2019:4021
Third Party Advisory
https://github.com/Netflix/security-bulletins/blob/master/advisories/third-party/2019-002.md
Third Party Advisory
https://kb.cert.org/vuls/id/605641/
Third Party Advisory
US Government Resource
https://kc.mcafee.com/corporate/index?page=content&id=SB10296
Third Party Advisory
https://security.netapp.com/advisory/ntap-20190823-0005/
Third Party Advisory
https://www.synology.com/security/advisory/Synology_SA_19_33
Third Party Advisory
http://seclists.org/fulldisclosure/2019/Aug/16
Third Party Advisory
Mailing List
https://access.redhat.com/errata/RHSA-2019:2766
Third Party Advisory
https://access.redhat.com/errata/RHSA-2019:2796
Third Party Advisory
https://access.redhat.com/errata/RHSA-2019:2861
Third Party Advisory
https://access.redhat.com/errata/RHSA-2019:4040
Third Party Advisory
https://access.redhat.com/errata/RHSA-2019:4041
Third Party Advisory
https://access.redhat.com/errata/RHSA-2019:4042
Third Party Advisory
https://access.redhat.com/errata/RHSA-2019:4045
Third Party Advisory
https://lists.apache.org/thread.html/392108390cef48af647a2e47b7fd5380e050e35ae8d1aa2030254c04%40%3Cusers.trafficserver.apache.org%3E
https://lists.apache.org/thread.html/ad3d01e767199c1aed8033bb6b3f5bf98c011c7c536f07a5d34b3c19%40%3Cannounce.trafficserver.apache.org%3E
https://lists.apache.org/thread.html/bde52309316ae798186d783a5e29f4ad1527f61c9219a289d0eee0a7%40%3Cdev.trafficserver.apache.org%3E
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4ZQGHE3WTYLYAYJEIDJVF2FIGQTAYPMC/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CMNFX5MNYRWWIMO4BTKYQCGUDMHO3AXP/
https://seclists.org/bugtraq/2019/Aug/24
Third Party Advisory
Mailing List
https://seclists.org/bugtraq/2019/Aug/43
Third Party Advisory
Mailing List
https://seclists.org/bugtraq/2019/Sep/18
Third Party Advisory
Mailing List
https://www.debian.org/security/2019/dsa-4508
Third Party Advisory
https://www.debian.org/security/2019/dsa-4520
Third Party Advisory
https://support.f5.com/csp/article/K50233772
Third Party Advisory
https://support.f5.com/csp/article/K50233772?utm_source=f5support&amp%3Butm_medium=RSS