CVE-2019-9518
published 2019-08-13CVE-2019-9518: Some HTTP/2 implementations are vulnerable to a flood of empty frames, potentially leading to a denial of service. The attacker sends a stream of frames with…
PriorityP351high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
25.45%
97.7th percentile
Some HTTP/2 implementations are vulnerable to a flood of empty frames, potentially leading to a denial of service. The attacker sends a stream of frames with an empty payload and without the end-of-stream flag. These frames can be DATA, HEADERS, CONTINUATION and/or PUSH_PROMISE. The peer spends time processing each frame disproportionate to attack bandwidth. This can consume excess CPU.
Affected
44 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | traffic_server | 6.0.0 – 6.2.3 | — |
| apache | traffic_server | 7.0.0 – 7.1.6 | — |
| apache | traffic_server | 8.0.0 – 8.0.3 | — |
| apple | swiftnio | 1.0.0 – 1.4.0 | — |
| apple | swiftnio_http_2 | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | trafficserver | < trafficserver 8.0.5+ds-1 (bookworm) | trafficserver 8.0.5+ds-1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| mcafee | web_gateway | >= 7.7.2.0 < 7.7.2.24 | 7.7.2.24 |
| mcafee | web_gateway | >= 7.8.2.0 < 7.8.2.13 | 7.8.2.13 |
| mcafee | web_gateway | >= 8.1.0 < 8.2.0 | 8.2.0 |
| msrc | windows_10 | — | — |
| msrc | windows_10_version_1607 | — | — |
| msrc | windows_10_version_1703 | — | — |
| msrc | windows_10_version_1709 | — | — |
| msrc | windows_10_version_1803 | — | — |
| msrc | windows_10_version_1809 | — | — |
| msrc | windows_10_version_1903 | — | — |
| msrc | windows_server_2016 | — | — |
| msrc | windows_server_2019 | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.07.8HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
osv7.5HIGH
vendor_debian7.5HIGH
vendor_msrc7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Netty vulnerabilities
vendor_ubuntu·2021-06-29·CVSS 7.5
CVE-2019-9514 [HIGH] Netty vulnerabilities
Title: Netty vulnerabilities
Summary: Several security issues were fixed in Netty.
It was discovered that Netty incorrectly implements HTTP/2. An attacker
could possibly use this issue to cause a denial of service. (CVE-2019-9512,
CVE-2019-9514, CVE-2019-9515, CVE-2019-9518)
Instructions: In general, a standard system update will make all the necessary changes.
Microsoft
HTTP/2 Server Denial of Service Vulnerability
vendor_msrc·2019-08-13·CVSS 7.5
CVE-2019-9518 [HIGH] HTTP/2 Server Denial of Service Vulnerability
HTTP/2 Server Denial of Service Vulnerability
Description: A denial of service vulnerability exists in the HTTP/2 protocol stack (HTTP.sys) when HTTP.sys improperly parses specially crafted HTTP/2 requests. An attacker who successfully exploited the vulnerability could create a denial of service condition, causing the target system to become unresponsive.
To exploit this vulnerability, an unauthenticated attacker could send a specially crafted HTTP packet to a target system, causing the affected system to become nonresponsive.
The update addresses the vulnerability by modifying how the Windows HTTP protocol stack handles HTTP/2 requests. Note that the denial of service vulnerability would not allow an attacker to execute code or to elevate user rights.
FAQ: After I install the HTTP/2 upd
Apple
CVE-2019-9518: SwiftNIO HTTP/2 1.5.0
vendor_apple·2019-08-13·CVSS 7.5
CVE-2019-9518 [HIGH] CVE-2019-9518: SwiftNIO HTTP/2 1.5.0
Apple Security Update: About the security content of SwiftNIO HTTP/2 1.5.0
Product: SwiftNIO HTTP/2
Version: 1.5.0
CVE: CVE-2019-9518
Component: SwiftNIO HTTP/2
Impact: A HTTP/2 server may consume excessive CPU resources when receiving certain traffic patterns
Description: This issue was addressed with improved input validation.
Red Hat
HTTP/2: flood using empty frames results in excessive resource consumption
vendor_redhat·2019-08-13·CVSS 7.5
CVE-2019-9518 [HIGH] CWE-400 HTTP/2: flood using empty frames results in excessive resource consumption
HTTP/2: flood using empty frames results in excessive resource consumption
Some HTTP/2 implementations are vulnerable to a flood of empty frames, potentially leading to a denial of service. The attacker sends a stream of frames with an empty payload and without the end-of-stream flag. These frames can be DATA, HEADERS, CONTINUATION and/or PUSH_PROMISE. The peer spends time processing each frame disproportionate to attack bandwidth. This can consume excess CPU.
A flaw was found in HTTP/2. Using frames with an empty payload, a flood could occur that results in excessive CPU usage and starvation of other clients. The highest threat from this vulnerability is to system availability.
Statement: This flaw has no available mitigation for nodejs package. It will be updated once the available fi
Debian
CVE-2019-9518: trafficserver - Some HTTP/2 implementations are vulnerable to a flood of empty frames, potential...
vendor_debian·2019·CVSS 7.5
CVE-2019-9518 [HIGH] CVE-2019-9518: trafficserver - Some HTTP/2 implementations are vulnerable to a flood of empty frames, potential...
Some HTTP/2 implementations are vulnerable to a flood of empty frames, potentially leading to a denial of service. The attacker sends a stream of frames with an empty payload and without the end-of-stream flag. These frames can be DATA, HEADERS, CONTINUATION and/or PUSH_PROMISE. The peer spends time processing each frame disproportionate to attack bandwidth. This can consume excess CPU.
Scope: local
bookworm: resolved (fixed in 8.0.5+ds-1)
bullseye: resolved (fixed in 8.0.5+ds-1)
sid: resolved (fixed in 8.0.5+ds-1)
GHSA
GHSA-93p3-5r25-4p75: Some HTTP/2 implementations are vulnerable to a flood of empty frames, potentially leading to a denial of service
ghsa_unreviewed·2022-05-24
CVE-2019-9518 [HIGH] CWE-400 GHSA-93p3-5r25-4p75: Some HTTP/2 implementations are vulnerable to a flood of empty frames, potentially leading to a denial of service
Some HTTP/2 implementations are vulnerable to a flood of empty frames, potentially leading to a denial of service. The attacker sends a stream of frames with an empty payload and without the end-of-stream flag. These frames can be DATA, HEADERS, CONTINUATION and/or PUSH_PROMISE. The peer spends time processing each frame disproportionate to attack bandwidth. This can consume excess CPU.
OSV
netty vulnerabilities
osv·2021-06-29·CVSS 7.5
CVE-2019-9512 [HIGH] netty vulnerabilities
netty vulnerabilities
It was discovered that Netty incorrectly implements HTTP/2. An attacker
could possibly use this issue to cause a denial of service. (CVE-2019-9512,
CVE-2019-9514, CVE-2019-9515, CVE-2019-9518)
OSV
CVE-2019-9518: Some HTTP/2 implementations are vulnerable to a flood of empty frames, potentially leading to a denial of service
osv·2019-08-13·CVSS 7.5
CVE-2019-9518 [HIGH] CVE-2019-9518: Some HTTP/2 implementations are vulnerable to a flood of empty frames, potentially leading to a denial of service
Some HTTP/2 implementations are vulnerable to a flood of empty frames, potentially leading to a denial of service. The attacker sends a stream of frames with an empty payload and without the end-of-stream flag. These frames can be DATA, HEADERS, CONTINUATION and/or PUSH_PROMISE. The peer spends time processing each frame disproportionate to attack bandwidth. This can consume excess CPU.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-9518 undertow: HTTP/2: flood using empty frames results in excessive resource consumption [fedora-all]
bugzilla·2019-09-03·CVSS 7.5
CVE-2019-9518 [HIGH] CVE-2019-9518 undertow: HTTP/2: flood using empty frames results in excessive resource consumption [fedora-all]
CVE-2019-9518 undertow: HTTP/2: flood using empty frames results in excessive resource consumption [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue a
Bugzilla
CVE-2019-9518 nodejs: HTTP/2: flood using empty frames results in excessive resources consumption [fedora-all]
bugzilla·2019-08-16·CVSS 7.5
CVE-2019-9518 [HIGH] CVE-2019-9518 nodejs: HTTP/2: flood using empty frames results in excessive resources consumption [fedora-all]
CVE-2019-9518 nodejs: HTTP/2: flood using empty frames results in excessive resources consumption [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue af
Bugzilla
CVE-2019-9518 nginx: HTTP/2: flood using empty frames results in excessive resource consumption [epel-all]
bugzilla·2019-08-16·CVSS 7.5
CVE-2019-9518 [HIGH] CVE-2019-9518 nginx: HTTP/2: flood using empty frames results in excessive resource consumption [epel-all]
CVE-2019-9518 nginx: HTTP/2: flood using empty frames results in excessive resource consumption [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects
Bugzilla
CVE-2019-9518 nodejs: HTTP/2: flood using empty frames results in excessive resource consumption [epel-all]
bugzilla·2019-08-16·CVSS 7.5
CVE-2019-9518 [HIGH] CVE-2019-9518 nodejs: HTTP/2: flood using empty frames results in excessive resource consumption [epel-all]
CVE-2019-9518 nodejs: HTTP/2: flood using empty frames results in excessive resource consumption [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects
Bugzilla
CVE-2019-9518 nginx: HTTP/2: flood using empty frames results in excessive resource consumption [fedora-all]
bugzilla·2019-08-16·CVSS 7.5
CVE-2019-9518 [HIGH] CVE-2019-9518 nginx: HTTP/2: flood using empty frames results in excessive resource consumption [fedora-all]
CVE-2019-9518 nginx: HTTP/2: flood using empty frames results in excessive resource consumption [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affe
Bugzilla
CVE-2019-9518 HTTP/2: flood using empty frames results in excessive resource consumption
bugzilla·2019-08-01·CVSS 7.5
CVE-2019-9518 [HIGH] CVE-2019-9518 HTTP/2: flood using empty frames results in excessive resource consumption
CVE-2019-9518 HTTP/2: flood using empty frames results in excessive resource consumption
HTTP/2 flood using frames with an empty payload that results in excessive CPU usage and starvation of other clients.
Discussion:
Acknowledgments:
Name: the Envoy security team
---
https://istio.io/blog/2019/announcing-1.2.4/
---
Created nodejs tracking bugs for this issue:
Affects: epel-all [bug 1741973]
Affects: fedora-all [bug 1741969]
---
Created nginx tracking bugs for this issue:
Affects: epel-all [bug 1742363]
Affects: fedora-all [bug 1742360]
---
External References:
https://github.com/Netflix/security-bulletins/blob/master/advisories/third-party/2019-002.md
https://nodejs.org/en/blog/vulnerability/aug-2019-security-releases/
---
NodeJS upstream commit for this issue:
https://gi
Tenable
Multiple Denial of Service (DoS) Vulnerabilities in HTTP/2 Disclosed (CVE-2019-9511, CVE-2019-9518)
blogs_tenable·2019-08-14·CVSS 7.5
[HIGH] Multiple Denial of Service (DoS) Vulnerabilities in HTTP/2 Disclosed (CVE-2019-9511, CVE-2019-9518)
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Talos
Microsoft Patch Tuesday — Aug. 2019: Vulnerability disclosures and Snort coverage
blogs_talos·2019-08-13·CVSS 9.1
[CRITICAL] Microsoft Patch Tuesday — Aug. 2019: Vulnerability disclosures and Snort coverage
Microsoft released its monthly security update today, disclosing a variety of vulnerabilities in several of its products. The latest Patch Tuesday covers 97 vulnerabilities, 31 of which are rated “critical," 65 that are considered "important" and one "moderate."
This month’s security update covers security issues in a variety of Microsoft services and software, including certain graphics components, Outlook and the Chakra Scripting Engine. For more on our coverage of these bugs, check out our Snort advisories here, covering all of the new rules we have for this release.
### Critical vulnerabilities Microsoft disclosed 31 critical vulnerabilities this month, three of which we will highlight below.
CVE-2019-1181 and CVE-2019-1182 are both remote code execution vulnerabilities in Remote De
Talos
Microsoft Patch Tuesday — Aug. 2019: Vulnerability disclosures and Snort coverage
blogs_talos·2019-08-13·CVSS 9.8
[CRITICAL] Microsoft Patch Tuesday — Aug. 2019: Vulnerability disclosures and Snort coverage
## Microsoft Patch Tuesday — Aug. 2019: Vulnerability disclosures and Snort coverage
Microsoft released its monthly security update today, disclosing a variety of vulnerabilities in several of its products. The latest Patch Tuesday covers 97 vulnerabilities, 31 of which are rated “critical," 65 that are considered "important" and one "moderate."
This month’s security update covers security issues in a variety of Microsoft services and software, including certain graphics components, Outlook and the Chakra Scripting Engine. For more on our coverage of these bugs, check out our Snort advisories here , covering all of the new rules we have for this release.
## Critical vulnerabilities Microsoft disclosed 31 critical vulnerabilities this month, three of which we will highlight below.
CVE-2
http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00031.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-09/msg00032.htmlhttp://seclists.org/fulldisclosure/2019/Aug/16https://access.redhat.com/errata/RHSA-2019:2925https://access.redhat.com/errata/RHSA-2019:2939https://access.redhat.com/errata/RHSA-2019:2955https://access.redhat.com/errata/RHSA-2019:3892https://access.redhat.com/errata/RHSA-2019:4352https://access.redhat.com/errata/RHSA-2020:0727https://github.com/Netflix/security-bulletins/blob/master/advisories/third-party/2019-002.mdhttps://kb.cert.org/vuls/id/605641/https://kc.mcafee.com/corporate/index?page=content&id=SB10296https://lists.apache.org/thread.html/091b518265bce56a16af87b77c8cfacda902a02079e866f9fdf13b61%40%3Cusers.trafficserver.apache.org%3Ehttps://lists.apache.org/thread.html/2653c56545573b528f3f6352a29eccaf498bd6fb2a6a59568d81a61d%40%3Cannounce.trafficserver.apache.org%3Ehttps://lists.apache.org/thread.html/9317fd092b257a0815434b116a8af8daea6e920b6673f4fd5583d5fe%40%3Ccommits.druid.apache.org%3Ehttps://lists.apache.org/thread.html/ff5b0821a6985159a832ff6d1a4bd311ac07ecc7db1e2d8bab619107%40%3Cdev.trafficserver.apache.org%3Ehttps://lists.apache.org/thread.html/r99a625fb17032646d96cd23dec49603ff630e9318e44a686d63046bc%40%3Ccommits.cassandra.apache.org%3Ehttps://lists.apache.org/thread.html/rd31230d01fa6aad18bdadc0720acd1747e53690bd35f73a48e7a9b75%40%3Ccommits.cassandra.apache.org%3Ehttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4ZQGHE3WTYLYAYJEIDJVF2FIGQTAYPMC/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CMNFX5MNYRWWIMO4BTKYQCGUDMHO3AXP/https://seclists.org/bugtraq/2019/Aug/24https://seclists.org/bugtraq/2019/Sep/18https://security.netapp.com/advisory/ntap-20190823-0005/https://support.f5.com/csp/article/K46011592https://support.f5.com/csp/article/K46011592?utm_source=f5support&%3Butm_medium=RSShttps://www.debian.org/security/2019/dsa-4520https://www.synology.com/security/advisory/Synology_SA_19_33http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00031.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-09/msg00032.htmlhttp://seclists.org/fulldisclosure/2019/Aug/16https://access.redhat.com/errata/RHSA-2019:2925https://access.redhat.com/errata/RHSA-2019:2939https://access.redhat.com/errata/RHSA-2019:2955https://access.redhat.com/errata/RHSA-2019:3892https://access.redhat.com/errata/RHSA-2019:4352https://access.redhat.com/errata/RHSA-2020:0727https://github.com/Netflix/security-bulletins/blob/master/advisories/third-party/2019-002.mdhttps://kb.cert.org/vuls/id/605641/https://kc.mcafee.com/corporate/index?page=content&id=SB10296https://lists.apache.org/thread.html/091b518265bce56a16af87b77c8cfacda902a02079e866f9fdf13b61%40%3Cusers.trafficserver.apache.org%3Ehttps://lists.apache.org/thread.html/2653c56545573b528f3f6352a29eccaf498bd6fb2a6a59568d81a61d%40%3Cannounce.trafficserver.apache.org%3Ehttps://lists.apache.org/thread.html/9317fd092b257a0815434b116a8af8daea6e920b6673f4fd5583d5fe%40%3Ccommits.druid.apache.org%3Ehttps://lists.apache.org/thread.html/ff5b0821a6985159a832ff6d1a4bd311ac07ecc7db1e2d8bab619107%40%3Cdev.trafficserver.apache.org%3Ehttps://lists.apache.org/thread.html/r99a625fb17032646d96cd23dec49603ff630e9318e44a686d63046bc%40%3Ccommits.cassandra.apache.org%3Ehttps://lists.apache.org/thread.html/rd31230d01fa6aad18bdadc0720acd1747e53690bd35f73a48e7a9b75%40%3Ccommits.cassandra.apache.org%3Ehttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4ZQGHE3WTYLYAYJEIDJVF2FIGQTAYPMC/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CMNFX5MNYRWWIMO4BTKYQCGUDMHO3AXP/https://seclists.org/bugtraq/2019/Aug/24https://seclists.org/bugtraq/2019/Sep/18https://security.netapp.com/advisory/ntap-20190823-0005/https://support.f5.com/csp/article/K46011592https://support.f5.com/csp/article/K46011592?utm_source=f5support&%3Butm_medium=RSShttps://www.debian.org/security/2019/dsa-4520https://www.synology.com/security/advisory/Synology_SA_19_33
2019-08-13
Published