CVE-2015-8659Improper Restriction of Operations within the Bounds of a Memory Buffer in Nghttp2

Severity
10.0CRITICALNVD
EPSS
2.2%
top 15.58%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 12
Latest updateMay 14

Description

The idle stream handling in nghttp2 before 1.6.0 allows attackers to have unspecified impact via unknown vectors, aka a heap-use-after-free bug.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:HExploitability: 3.9 | Impact: 6.0

Affected Packages11 packages

debiandebian/nghttp2< nghttp2 1.6.0-1 (bookworm)
Debiannghttp2/nghttp2< 1.6.0-1+3
NVDnghttp2/nghttp21.5.0
NVDapple/tvos9.1
NVDapple/watchos2.1

Patches

🔴Vulnerability Details

2
GHSA
GHSA-v339-2hrg-v7hm: The idle stream handling in nghttp2 before 12022-05-14
OSV
CVE-2015-8659: The idle stream handling in nghttp2 before 12016-01-12

📋Vendor Advisories

5
Debian
CVE-2015-8659: nghttp2 - The idle stream handling in nghttp2 before 1.6.0 allows attackers to have unspec...2015
Apple
CVE-2015-8659: iOS 9.3
Apple
CVE-2015-8659: OS X El Capitan v10.11.4 and Security Update 2016-002
Apple
CVE-2015-8659: watchOS 2.2
Apple
CVE-2015-8659: tvOS 9.2

💬Community

3
Bugzilla
CVE-2015-8659 nghttp2: heap-use-after-free flaw in idle stream handling code2016-01-04
Bugzilla
CVE-2015-8659 nghttp2: heap-use-after-free flaw in idle stream handling code [epel-7]2016-01-04
Bugzilla
CVE-2015-8659 nghttp2: heap-use-after-free flaw in idle stream handling code [fedora-all]2016-01-04