[FEDORA-2019-63ba15cc83] Fedora 30: mod_http2

Severity High
Affected Packages 1
CVEs 3

Rebuilt with newer nghttp2 ---- This update includes the latest upstream
release of mod_http2, version 1.15.3. Upstream changes include: * fixes
Timeout vs. KeepAliveTimeout behaviour, see PR 63534. * Fixes stream cleanup
when connection throttling is in place. * Counts stream resets by client on
streams initiated by client as cause for connection throttling. * Header length
checks are now logged similar to HTTP/1.1 protocol handler * Header length is
checked also on the merged value from several header instances and results in a
431 response. * fixing mod_proxy_http2 to support trailers in both directions.
See PR 63502.

Package Affected Version
pkg:rpm/fedora/mod_http2?distro=fedora-30 < 1.15.3.2.fc30
ID
FEDORA-2019-63ba15cc83
Severity
high
Severity from
CVE-2019-9511
URL
https://bodhi.fedoraproject.org/updates/FEDORA-2019-63ba15cc83
Published
2019-08-30T14:21:13
(5 years ago)
Modified
2019-08-30T14:21:13
(5 years ago)
Rights
Copyright 2019 Red Hat, Inc.
Other Advisories
Source # ID Name URL
Bugzilla 1741948 Bug #1741948 - CVE-2019-9511 CVE-2019-9516 CVE-2019-9517 mod_http2: various flaws [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1741948
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:rpm/fedora/mod_http2?distro=fedora-30 fedora mod_http2 < 1.15.3.2.fc30 fedora-30
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...