[ALAS-2023-1869] Amazon Linux AMI 2014.03 - ALAS-2023-1869: important priority package update for nghttp2

Severity Important
Affected Packages 8
CVEs 1

Package updates are available for Amazon Linux AMI that fix the following vulnerabilities:
CVE-2023-44487:
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.

ID
ALAS-2023-1869
Severity
important
URL
https://alas.aws.amazon.com/ALAS-2023-1869.html
Published
2023-10-16T13:45:00
(11 months ago)
Modified
2023-10-18T20:10:00
(11 months ago)
Rights
Amazon Linux Security Team
Other Advisories
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:rpm/amazonlinux/nghttp2?arch=x86_64&distro=amazonlinux-1 amazonlinux nghttp2 < 1.33.0-1.1.8.amzn1 amazonlinux-1 x86_64
Affected pkg:rpm/amazonlinux/nghttp2?arch=i686&distro=amazonlinux-1 amazonlinux nghttp2 < 1.33.0-1.1.8.amzn1 amazonlinux-1 i686
Affected pkg:rpm/amazonlinux/nghttp2-debuginfo?arch=x86_64&distro=amazonlinux-1 amazonlinux nghttp2-debuginfo < 1.33.0-1.1.8.amzn1 amazonlinux-1 x86_64
Affected pkg:rpm/amazonlinux/nghttp2-debuginfo?arch=i686&distro=amazonlinux-1 amazonlinux nghttp2-debuginfo < 1.33.0-1.1.8.amzn1 amazonlinux-1 i686
Affected pkg:rpm/amazonlinux/libnghttp2?arch=x86_64&distro=amazonlinux-1 amazonlinux libnghttp2 < 1.33.0-1.1.8.amzn1 amazonlinux-1 x86_64
Affected pkg:rpm/amazonlinux/libnghttp2?arch=i686&distro=amazonlinux-1 amazonlinux libnghttp2 < 1.33.0-1.1.8.amzn1 amazonlinux-1 i686
Affected pkg:rpm/amazonlinux/libnghttp2-devel?arch=x86_64&distro=amazonlinux-1 amazonlinux libnghttp2-devel < 1.33.0-1.1.8.amzn1 amazonlinux-1 x86_64
Affected pkg:rpm/amazonlinux/libnghttp2-devel?arch=i686&distro=amazonlinux-1 amazonlinux libnghttp2-devel < 1.33.0-1.1.8.amzn1 amazonlinux-1 i686
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...