[VU:605641] HTTP/2 implementations do not robustly handle abnormal traffic and resource exhaustion

Severity High
CVEs 8

Overview

Multiple HTTP/2 implementations are vulnerable to a variety of denial-of-service (DoS) attacks.

Impact

These attacks can consume excessive system resources, potentially enough that a single end-system could cause issues on multiple servers that may lead to Distributed DoS (DDoS) attacks.

Solution

Apply an update
Install the latest updates from HTTP/2 implementers.

Acknowledgements

Thanks to Jonathan Looney of Netflix for reporting CVE-2019-9511,CVE-2019-9512,CVE-2019-9513,CVE-2019-9514,CVE-2019-9515,CVE-2019-9516,and CVE-2019-9517. Thanks to Piotr Sikora of Google,Envoy Security Team,for reporting CVE-2019-9518.

ID
VU:605641
Severity
high
Severity from
CVE-2019-9511
URL
https://kb.cert.org/vuls/id/605641
Published
2019-08-13T17:43:09
(5 years ago)
Modified
2019-11-19T21:13:43
(4 years ago)
Rights
Copyright 2019, CERT Coordination Center (CERT/CC)
Other Advisories
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...