cbcvebase.
CVE-2019-9512
published 2019-08-13

CVE-2019-9512: Some HTTP/2 implementations are vulnerable to ping floods, potentially leading to a denial of service. The attacker sends continual pings to an HTTP/2 peer…

high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
Some HTTP/2 implementations are vulnerable to ping floods, potentially leading to a denial of service. The attacker sends continual pings to an HTTP/2 peer, causing the peer to build an internal queue of responses. Depending on how efficiently this data is queued, this can consume excess CPU, memory, or both.

Affected

33 ranges· showing 25
VendorProductVersion rangeFixed in
apachetraffic_server6.0.0 – 6.2.3
apachetraffic_server7.0.0 – 7.1.6
apachetraffic_server8.0.0 – 8.0.3
appleswiftnio1.0.0 – 1.4.0
appleswiftnio_http_2
debiandebian_linux
debianh2o< h2o 2.2.5+dfsg2-3 (bookworm)h2o 2.2.5+dfsg2-3 (bookworm)
debiantrafficserver< h2o 2.2.5+dfsg2-3 (bookworm)h2o 2.2.5+dfsg2-3 (bookworm)
golang.orgx_net>= 0 < 0.0.0-20190813141303-74dc4d7220e70.0.0-20190813141303-74dc4d7220e7
h2oh2o>= 0 < 2.2.5+dfsg2-32.2.5+dfsg2-3
h2oh2o>= 0 < 2.2.5+dfsg2-32.2.5+dfsg2-3
msrcwindows_10
msrcwindows_10_version_1607
msrcwindows_10_version_1703
msrcwindows_10_version_1709
msrcwindows_10_version_1803
msrcwindows_10_version_1809
msrcwindows_10_version_1903
msrcwindows_server_2016
msrcwindows_server_2019
msrcwindows_server_version_1709
msrcwindows_server_version_1803
msrcwindows_server_version_1903
nettynetty>= 0 < 1:4.1.7-4ubuntu0.1+esm11:4.1.7-4ubuntu0.1+esm1
nodejsnode.js10.0.0 – 10.12.0

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
ghsa7.5HIGH
osv7.5HIGH