CVE-2015-8659 — Improper Restriction of Operations within the Bounds of a Memory Buffer in Nghttp2
CWE-119 — Improper Restriction of Operations within the Bounds of a Memory Buffer11 documents6 sources
Severity
10.0CRITICALNVD
EPSS
2.2%
top 15.58%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJan 12
Latest updateMay 14
Description
The idle stream handling in nghttp2 before 1.6.0 allows attackers to have unspecified impact via unknown vectors, aka a heap-use-after-free bug.
CVSS vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:HExploitability: 3.9 | Impact: 6.0
Affected Packages11 packages
Patches
🔴Vulnerability Details
2📋Vendor Advisories
5💬Community
3Bugzilla
▶
Bugzilla▶
CVE-2015-8659 nghttp2: heap-use-after-free flaw in idle stream handling code [fedora-all]↗2016-01-04