cbcvebase.
CVE-2019-9518
published 2019-08-13

CVE-2019-9518: Some HTTP/2 implementations are vulnerable to a flood of empty frames, potentially leading to a denial of service. The attacker sends a stream of frames with…

high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
Some HTTP/2 implementations are vulnerable to a flood of empty frames, potentially leading to a denial of service. The attacker sends a stream of frames with an empty payload and without the end-of-stream flag. These frames can be DATA, HEADERS, CONTINUATION and/or PUSH_PROMISE. The peer spends time processing each frame disproportionate to attack bandwidth. This can consume excess CPU.

Affected

44 ranges· showing 25
VendorProductVersion rangeFixed in
apachetraffic_server6.0.0 – 6.2.3
apachetraffic_server7.0.0 – 7.1.6
apachetraffic_server8.0.0 – 8.0.3
appleswiftnio1.0.0 – 1.4.0
appleswiftnio_http_2
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debiandebian_linux
debiandebian_linux
debiantrafficserver< trafficserver 8.0.5+ds-1 (bookworm)trafficserver 8.0.5+ds-1 (bookworm)
fedoraprojectfedora
fedoraprojectfedora
mcafeeweb_gateway>= 7.7.2.0 < 7.7.2.247.7.2.24
mcafeeweb_gateway>= 7.8.2.0 < 7.8.2.137.8.2.13
mcafeeweb_gateway>= 8.1.0 < 8.2.08.2.0
msrcwindows_10
msrcwindows_10_version_1607
msrcwindows_10_version_1703
msrcwindows_10_version_1709
msrcwindows_10_version_1803
msrcwindows_10_version_1809
msrcwindows_10_version_1903
msrcwindows_server_2016
msrcwindows_server_2019

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH