[FREEBSD:121FEC01-C042-11E9-A73F-B36F5969F162] nghttp2 -- multiple vulnerabilities

Severity High
Affected Packages 1
CVEs 2

nghttp2 GitHub releases:

  This release fixes CVE-2019-9511 "Data Dribble" and CVE-2019-9513
    "Resource Loop" vulnerability in nghttpx and nghttpd. Specially crafted
    HTTP/2 frames cause Denial of Service by consuming CPU time. Check out
    for details. For nghttpx, additionally limiting inbound traffic by
    --read-rate and --read-burst options is quite effective against this
    kind of attack.
  CVE-2019-9511 "Data Dribble": The attacker requests a large amount of
    data from a specified resource over multiple streams. They manipulate
    window size and stream priority to force the server to queue the data in
    1-byte chunks. Depending on how efficiently this data is queued, this
    can consume excess CPU, memory, or both, potentially leading to a
    denial of service.
  CVE-2019-9513 "Ping Flood": The attacker sends continual pings to an
    HTTP/2 peer, causing the peer to build an internal queue of responses.
    Depending on how efficiently this data is queued, this can consume
    excess CPU, memory, or both, potentially leading to a denial of service.
Package Affected Version
pkg:freebsd/libnghttp2 < 1.39.2
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:freebsd/libnghttp2 libnghttp2 < 1.39.2
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date