cbcvebase.
CVE-2019-9514
published 2019-08-13

CVE-2019-9514: Some HTTP/2 implementations are vulnerable to a reset flood, potentially leading to a denial of service. The attacker opens a number of streams and sends an…

high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
Some HTTP/2 implementations are vulnerable to a reset flood, potentially leading to a denial of service. The attacker opens a number of streams and sends an invalid request over each stream that should solicit a stream of RST_STREAM frames from the peer. Depending on how the peer queues the RST_STREAM frames, this can consume excess memory, CPU, or both.

Affected

75 ranges· showing 25
VendorProductVersion rangeFixed in
apachetraffic_server6.0.0 – 6.2.3
apachetraffic_server7.0.0 – 7.1.6
apachetraffic_server8.0.0 – 8.0.3
appleswiftnio1.0.0 – 1.4.0
appleswiftnio_http_2
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debiandebian_linux
debiandebian_linux
debianh2o< h2o 2.2.5+dfsg2-3 (bookworm)h2o 2.2.5+dfsg2-3 (bookworm)
debiannodejs< h2o 2.2.5+dfsg2-3 (bookworm)h2o 2.2.5+dfsg2-3 (bookworm)
debianrust-h2< h2o 2.2.5+dfsg2-3 (bookworm)h2o 2.2.5+dfsg2-3 (bookworm)
debiantrafficserver< h2o 2.2.5+dfsg2-3 (bookworm)h2o 2.2.5+dfsg2-3 (bookworm)
f5big-ip_local_traffic_manager>= 11.6.1 < 11.6.5.111.6.5.1
f5big-ip_local_traffic_manager>= 12.1.0 < 12.1.5.112.1.5.1
f5big-ip_local_traffic_manager>= 13.1.0 < 13.1.3.213.1.3.2
f5big-ip_local_traffic_manager>= 14.0.0 < 14.0.1.114.0.1.1
f5big-ip_local_traffic_manager>= 14.1.0 < 14.1.2.114.1.2.1
f5big-ip_local_traffic_manager>= 15.0.0 < 15.0.1.115.0.1.1
fedoraprojectfedora
fedoraprojectfedora
golang.orgx_net>= 0 < 0.0.0-20190813141303-74dc4d7220e70.0.0-20190813141303-74dc4d7220e7
h2oh2o>= 0 < 2.2.5+dfsg2-32.2.5+dfsg2-3
h2oh2o>= 0 < 2.2.5+dfsg2-32.2.5+dfsg2-3

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
ghsa7.5HIGH
osv7.5HIGH