ISOMAN

CVE

CVE-2019-9517

Some HTTP/2 implementations are vulnerable to unconstrained interal data buffering, potentially leading to a denial of service. The attacker opens the HTTP/2 window so the peer can send without constraint; however, they leave the TCP window closed so the peer cannot actually write (many of) the bytes on the wire. The attacker then sends a stream of requests for a large response object. Depending on how the servers queue the responses, this can consume excess memory, CPU, or both.

Severity
HIGH
CVSS
7.5
Published
Modified

Linked Releases

References

  1. http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00004.html
  2. http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00031.html
  3. http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00032.html
  4. http://www.openwall.com/lists/oss-security/2019/08/15/7
  5. https://access.redhat.com/errata/RHSA-2019:2893
  6. https://access.redhat.com/errata/RHSA-2019:2925
  7. https://access.redhat.com/errata/RHSA-2019:2939
  8. https://access.redhat.com/errata/RHSA-2019:2946
  9. https://access.redhat.com/errata/RHSA-2019:2949
  10. https://access.redhat.com/errata/RHSA-2019:2950
  11. https://access.redhat.com/errata/RHSA-2019:2955
  12. https://access.redhat.com/errata/RHSA-2019:3932
  13. https://access.redhat.com/errata/RHSA-2019:3933
  14. https://access.redhat.com/errata/RHSA-2019:3935
  15. https://github.com/Netflix/security-bulletins/blob/master/advisories/third-party/2019-002.md
  16. https://kb.cert.org/vuls/id/605641/
  17. https://kc.mcafee.com/corporate/index?page=content&id=SB10296
  18. https://lists.apache.org/thread.html/4610762456644181b267c846423b3a990bd4aaea1886ecc7d51febdb%40%3Cannounce.httpd.apache.org%3E
  19. https://lists.apache.org/thread.html/56c2e7cc9deb1c12a843d0dc251ea7fd3e7e80293cde02fcd65286ba%40%3Ccvs.httpd.apache.org%3E
  20. https://lists.apache.org/thread.html/d89f999e26dfb1d50f247ead1fe8538014eb412b2dbe5be4b1a9ef50%40%3Cdev.httpd.apache.org%3E