6.8

CVE-2019-9516

Some HTTP/2 implementations are vulnerable to a header leak, potentially leading to a denial of service

Some HTTP/2 implementations are vulnerable to a header leak, potentially leading to a denial of service. The attacker sends a stream of headers with a 0-length header name and 0-length header value, optionally Huffman encoded into 1-byte or greater headers. Some implementations allocate memory for these headers and keep the allocation alive until the session dies. This can consume excess memory.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Apple ≫ Swiftnio Version >= 1.0.0 <= 1.4.0
   Apple ≫ macOS X Version >= 10.12
   Canonical ≫ Ubuntu Linux Version >= 14.04
Apache ≫ Traffic Server Version >= 6.0.0 <= 6.2.3
Apache ≫ Traffic Server Version >= 7.0.0 <= 7.1.6
Apache ≫ Traffic Server Version >= 8.0.0 <= 8.0.3
Canonical ≫ Ubuntu Linux Version 16.04 SwEdition lts
Canonical ≫ Ubuntu Linux Version 18.04 SwEdition lts
Canonical ≫ Ubuntu Linux Version 19.04
Debian ≫ Debian Linux Version 9.0
Debian ≫ Debian Linux Version 10.0
Fedoraproject ≫ Fedora Version 30
Synology ≫ Skynas Version -
Synology ≫ Diskstation Manager Version 6.2
Synology ≫ Vs960hd Firmware Version -
   Synology ≫ Vs960hd Version -
Debian ≫ Debian Linux Version 9.0
Debian ≫ Debian Linux Version 10.0
Fedoraproject ≫ Fedora Version 29
Fedoraproject ≫ Fedora Version 30
Fedoraproject ≫ Fedora Version 32
Opensuse ≫ Leap Version 15.0
Opensuse ≫ Leap Version 15.1
Redhat ≫ Jboss Core Services Version 1.0
Redhat ≫ Openshift Service Mesh Version 1.0
Redhat ≫ Quay Version 3.0.0
Redhat ≫ Software Collections Version 1.0
Redhat ≫ Enterprise Linux Version 8.0
Oracle ≫ Graalvm Version 19.2.0 SwEdition enterprise
Mcafee ≫ Web Gateway Version >= 7.7.2.0 < 7.7.2.24
Mcafee ≫ Web Gateway Version >= 7.8.2.0 < 7.8.2.13
Mcafee ≫ Web Gateway Version >= 8.1.0 < 8.2.0
F5 ≫ Nginx Version >= 1.9.5 < 1.16.1
F5 ≫ Nginx Version >= 1.17.0 <= 1.17.2
Nodejs ≫ Node.Js SwEdition lts Version >= 8.0.0 < 8.16.1
Nodejs ≫ Node.Js SwEdition lts Version >= 10.0.0 < 10.16.3
Nodejs ≫ Node.Js SwEdition - Version >= 12.0.0 < 12.8.1
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 56.26% 0.989
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6.5 2.8 3.6
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
NIST 6.8 8 6.9
AV:N/AC:L/Au:S/C:N/I:N/A:C
CERT.org 7.5 3.9 3.6
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CWE-400 Uncontrolled Resource Consumption

The product does not properly control the allocation and maintenance of a limited resource.

CWE-770 Allocation of Resources Without Limits or Throttling

The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.

https://access.redhat.com/errata/RHSA-2019:3932
Third Party Advisory
https://access.redhat.com/errata/RHSA-2019:3933
Third Party Advisory
https://access.redhat.com/errata/RHSA-2019:3935
Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00035.html
Third Party Advisory
Mailing List
http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00031.html
Third Party Advisory
Mailing List
http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00032.html
Third Party Advisory
Mailing List
http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00014.html
Third Party Advisory
Mailing List
https://access.redhat.com/errata/RHSA-2019:2745
Third Party Advisory
https://access.redhat.com/errata/RHSA-2019:2746
Third Party Advisory
https://access.redhat.com/errata/RHSA-2019:2775
Third Party Advisory
https://access.redhat.com/errata/RHSA-2019:2799
Third Party Advisory
https://access.redhat.com/errata/RHSA-2019:2925
Third Party Advisory
https://access.redhat.com/errata/RHSA-2019:2939
Third Party Advisory
https://access.redhat.com/errata/RHSA-2019:2955
Third Party Advisory
https://access.redhat.com/errata/RHSA-2019:2966
Third Party Advisory
https://github.com/Netflix/security-bulletins/blob/master/advisories/third-party/2019-002.md
Third Party Advisory
https://kb.cert.org/vuls/id/605641/
Third Party Advisory
US Government Resource
https://kc.mcafee.com/corporate/index?page=content&id=SB10296
Third Party Advisory
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BP556LEG3WENHZI5TAQ6ZEBFTJB4E2IS/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/POPAEC4FWL4UU4LDEGPY5NPALU24FFQD/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TAZZEVTCN2B4WT6AIBJ7XGYJMBTORJU5/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XHTKU7YQ5EEP2XNSAV4M4VJ7QCBOJMOD/
https://seclists.org/bugtraq/2019/Aug/40
Third Party Advisory
Mailing List
https://security.netapp.com/advisory/ntap-20190823-0002/
Third Party Advisory
https://security.netapp.com/advisory/ntap-20190823-0005/
Third Party Advisory
https://support.f5.com/csp/article/K02591030
Third Party Advisory
https://support.f5.com/csp/article/K02591030?utm_source=f5support&amp%3Butm_medium=RSS
https://usn.ubuntu.com/4099-1/
Third Party Advisory
https://www.debian.org/security/2019/dsa-4505
Third Party Advisory
https://www.synology.com/security/advisory/Synology_SA_19_33
Third Party Advisory
http://seclists.org/fulldisclosure/2019/Aug/16
Third Party Advisory
Mailing List
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4ZQGHE3WTYLYAYJEIDJVF2FIGQTAYPMC/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CMNFX5MNYRWWIMO4BTKYQCGUDMHO3AXP/
https://seclists.org/bugtraq/2019/Aug/24
Third Party Advisory
Mailing List
https://access.redhat.com/errata/RHSA-2019:2946
Third Party Advisory
https://access.redhat.com/errata/RHSA-2019:2950
Third Party Advisory
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/H472D5HPXN6RRXCNFML3BK5OYC52CXF2/