ISOMAN

CVE

CVE-2019-9516

Some HTTP/2 implementations are vulnerable to a header leak, potentially leading to a denial of service. The attacker sends a stream of headers with a 0-length header name and 0-length header value, optionally Huffman encoded into 1-byte or greater headers. Some implementations allocate memory for these headers and keep the allocation alive until the session dies. This can consume excess memory.

Severity
MEDIUM
CVSS
6.5
Published
Modified

Linked Releases

References

  1. http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00031.html
  2. http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00032.html
  3. http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00035.html
  4. http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00014.html
  5. http://seclists.org/fulldisclosure/2019/Aug/16
  6. https://access.redhat.com/errata/RHSA-2019:2745
  7. https://access.redhat.com/errata/RHSA-2019:2746
  8. https://access.redhat.com/errata/RHSA-2019:2775
  9. https://access.redhat.com/errata/RHSA-2019:2799
  10. https://access.redhat.com/errata/RHSA-2019:2925
  11. https://access.redhat.com/errata/RHSA-2019:2939
  12. https://access.redhat.com/errata/RHSA-2019:2946
  13. https://access.redhat.com/errata/RHSA-2019:2950
  14. https://access.redhat.com/errata/RHSA-2019:2955
  15. https://access.redhat.com/errata/RHSA-2019:2966
  16. https://access.redhat.com/errata/RHSA-2019:3932
  17. https://access.redhat.com/errata/RHSA-2019:3933
  18. https://access.redhat.com/errata/RHSA-2019:3935
  19. https://github.com/Netflix/security-bulletins/blob/master/advisories/third-party/2019-002.md
  20. https://kb.cert.org/vuls/id/605641/