cbcvebase.
CVE-2019-9516
published 2019-08-13

CVE-2019-9516: Some HTTP/2 implementations are vulnerable to a header leak, potentially leading to a denial of service. The attacker sends a stream of headers with a 0-length…

medium6.5CVSS 3.1
AVNACLPRLUINSUCNINAH
Some HTTP/2 implementations are vulnerable to a header leak, potentially leading to a denial of service. The attacker sends a stream of headers with a 0-length header name and 0-length header value, optionally Huffman encoded into 1-byte or greater headers. Some implementations allocate memory for these headers and keep the allocation alive until the session dies. This can consume excess memory.

Affected

40 ranges· showing 25
VendorProductVersion rangeFixed in
apachetraffic_server6.0.0 – 6.2.3
apachetraffic_server7.0.0 – 7.1.6
apachetraffic_server8.0.0 – 8.0.3
appleswiftnio1.0.0 – 1.4.0
appleswiftnio_http_2
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debiandebian_linux
debiandebian_linux
debiannginx< nginx 1.14.2-3 (bookworm)nginx 1.14.2-3 (bookworm)
f5nginx>= 0 < 1.14.2-31.14.2-3
f5nginx>= 0 < 1.14.2-31.14.2-3
f5nginx>= 0 < 1.14.2-31.14.2-3
f5nginx>= 0 < 1.14.2-31.14.2-3
f5nginx1.17.0 – 1.17.2
f5nginx>= 1.9.5 < 1.16.11.16.1
fedoraprojectfedora
fedoraprojectfedora
fedoraprojectfedora
mcafeeweb_gateway>= 7.7.2.0 < 7.7.2.247.7.2.24
mcafeeweb_gateway>= 7.8.2.0 < 7.8.2.137.8.2.13
mcafeeweb_gateway>= 8.1.0 < 8.2.08.2.0
msrccbl_mariner_1.0_arm
msrccbl_mariner_1.0_x64

CVSS provenance

nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv6.5MEDIUM