cbcvebase.
CVE-2019-9511
published 2019-08-13

CVE-2019-9511: Some HTTP/2 implementations are vulnerable to window size manipulation and stream prioritization manipulation, potentially leading to a denial of service. The…

high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
Some HTTP/2 implementations are vulnerable to window size manipulation and stream prioritization manipulation, potentially leading to a denial of service. The attacker requests a large amount of data from a specified resource over multiple streams. They manipulate window size and stream priority to force the server to queue the data in 1-byte chunks. Depending on how efficiently this data is queued, this can consume excess CPU, memory, or both.

Affected

90 ranges· showing 25
VendorProductVersion rangeFixed in
apachetraffic_server6.0.0 – 6.2.3
apachetraffic_server7.0.0 – 7.1.6
apachetraffic_server8.0.0 – 8.0.3
appleswiftnio1.0.0 – 1.4.0
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debiandebian_linux
debiandebian_linux
debiannghttp2< nghttp2 1.39.2-1 (bookworm)nghttp2 1.39.2-1 (bookworm)
debiannginx< nghttp2 1.39.2-1 (bookworm)nghttp2 1.39.2-1 (bookworm)
debiannodejs< nghttp2 1.39.2-1 (bookworm)nghttp2 1.39.2-1 (bookworm)
f5nginx>= 0 < 1.14.2-31.14.2-3
f5nginx>= 0 < 1.14.2-31.14.2-3
f5nginx>= 0 < 1.14.2-31.14.2-3
f5nginx>= 0 < 1.14.2-31.14.2-3
f5nginx1.17.0 – 1.17.2
f5nginx>= 1.9.5 < 1.16.11.16.1
fedoraprojectfedora
fedoraprojectfedora
mcafeeactive_response
mcafeeactive_response
mcafeeactive_response
mcafeeactive_response
mcafeeactive_response

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH