[ALAS2-2019-1298] Amazon Linux 2 2017.12 - ALAS2-2019-1298: important priority package update for nghttp2

Severity Important
Affected Packages 12
CVEs 2

Package updates are available for Amazon Linux 2 that fix the following vulnerabilities:
CVE-2019-9513:
Some HTTP/2 implementations are vulnerable to resource loops, potentially leading to a denial of service. The attacker creates multiple request streams and continually shuffles the priority of the streams in a way that causes substantial churn to the priority tree. This can consume excess CPU.
1735741:
CVE-2019-9513 HTTP/2: flood using PRIORITY frames results in excessive resource consumption

CVE-2019-9511:
Some HTTP/2 implementations are vulnerable to window size manipulation and stream prioritization manipulation, potentially leading to a denial of service. The attacker requests a large amount of data from a specified resource over multiple streams. They manipulate window size and stream priority to force the server to queue the data in 1-byte chunks. Depending on how efficiently this data is queued, this can consume excess CPU, memory, or both.
1741860:
CVE-2019-9511 HTTP/2: large amount of data requests leads to denial of service

Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:rpm/amazonlinux/nghttp2?arch=x86_64&distro=amazonlinux-2 amazonlinux nghttp2 < 1.39.2-1.amzn2 amazonlinux-2 x86_64
Affected pkg:rpm/amazonlinux/nghttp2?arch=i686&distro=amazonlinux-2 amazonlinux nghttp2 < 1.39.2-1.amzn2 amazonlinux-2 i686
Affected pkg:rpm/amazonlinux/nghttp2?arch=aarch64&distro=amazonlinux-2 amazonlinux nghttp2 < 1.39.2-1.amzn2 amazonlinux-2 aarch64
Affected pkg:rpm/amazonlinux/nghttp2-debuginfo?arch=x86_64&distro=amazonlinux-2 amazonlinux nghttp2-debuginfo < 1.39.2-1.amzn2 amazonlinux-2 x86_64
Affected pkg:rpm/amazonlinux/nghttp2-debuginfo?arch=i686&distro=amazonlinux-2 amazonlinux nghttp2-debuginfo < 1.39.2-1.amzn2 amazonlinux-2 i686
Affected pkg:rpm/amazonlinux/nghttp2-debuginfo?arch=aarch64&distro=amazonlinux-2 amazonlinux nghttp2-debuginfo < 1.39.2-1.amzn2 amazonlinux-2 aarch64
Affected pkg:rpm/amazonlinux/libnghttp2?arch=x86_64&distro=amazonlinux-2 amazonlinux libnghttp2 < 1.39.2-1.amzn2 amazonlinux-2 x86_64
Affected pkg:rpm/amazonlinux/libnghttp2?arch=i686&distro=amazonlinux-2 amazonlinux libnghttp2 < 1.39.2-1.amzn2 amazonlinux-2 i686
Affected pkg:rpm/amazonlinux/libnghttp2?arch=aarch64&distro=amazonlinux-2 amazonlinux libnghttp2 < 1.39.2-1.amzn2 amazonlinux-2 aarch64
Affected pkg:rpm/amazonlinux/libnghttp2-devel?arch=x86_64&distro=amazonlinux-2 amazonlinux libnghttp2-devel < 1.39.2-1.amzn2 amazonlinux-2 x86_64
Affected pkg:rpm/amazonlinux/libnghttp2-devel?arch=i686&distro=amazonlinux-2 amazonlinux libnghttp2-devel < 1.39.2-1.amzn2 amazonlinux-2 i686
Affected pkg:rpm/amazonlinux/libnghttp2-devel?arch=aarch64&distro=amazonlinux-2 amazonlinux libnghttp2-devel < 1.39.2-1.amzn2 amazonlinux-2 aarch64
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...