[USN-6142-1] nghttp2 vulnerability

Severity High
Affected Packages 21
CVEs 1

nghttp2 could be made to crash if it opened a specially crafted file.

Gal Goldshtein discovered that nghttp2 incorrectly handled certain inputs. If
a user or an automated system were tricked into opening a specially crafted
input file, a remote attacker could possibly use this issue to cause a
denial of service.

Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:deb/ubuntu/nghttp2?distro=xenial ubuntu nghttp2 < 1.7.1-1ubuntu0.1~esm1 xenial
Affected pkg:deb/ubuntu/nghttp2?distro=focal ubuntu nghttp2 < 1.40.0-1ubuntu0.1 focal
Affected pkg:deb/ubuntu/nghttp2?distro=bionic ubuntu nghttp2 < 1.30.0-1ubuntu1+esm1 bionic
Affected pkg:deb/ubuntu/nghttp2-server?distro=xenial ubuntu nghttp2-server < 1.7.1-1ubuntu0.1~esm1 xenial
Affected pkg:deb/ubuntu/nghttp2-server?distro=focal ubuntu nghttp2-server < 1.40.0-1ubuntu0.1 focal
Affected pkg:deb/ubuntu/nghttp2-server?distro=bionic ubuntu nghttp2-server < 1.30.0-1ubuntu1+esm1 bionic
Affected pkg:deb/ubuntu/nghttp2-proxy?distro=xenial ubuntu nghttp2-proxy < 1.7.1-1ubuntu0.1~esm1 xenial
Affected pkg:deb/ubuntu/nghttp2-proxy?distro=focal ubuntu nghttp2-proxy < 1.40.0-1ubuntu0.1 focal
Affected pkg:deb/ubuntu/nghttp2-proxy?distro=bionic ubuntu nghttp2-proxy < 1.30.0-1ubuntu1+esm1 bionic
Affected pkg:deb/ubuntu/nghttp2-client?distro=xenial ubuntu nghttp2-client < 1.7.1-1ubuntu0.1~esm1 xenial
Affected pkg:deb/ubuntu/nghttp2-client?distro=focal ubuntu nghttp2-client < 1.40.0-1ubuntu0.1 focal
Affected pkg:deb/ubuntu/nghttp2-client?distro=bionic ubuntu nghttp2-client < 1.30.0-1ubuntu1+esm1 bionic
Affected pkg:deb/ubuntu/libnghttp2-doc?distro=xenial ubuntu libnghttp2-doc < 1.7.1-1ubuntu0.1~esm1 xenial
Affected pkg:deb/ubuntu/libnghttp2-doc?distro=focal ubuntu libnghttp2-doc < 1.40.0-1ubuntu0.1 focal
Affected pkg:deb/ubuntu/libnghttp2-doc?distro=bionic ubuntu libnghttp2-doc < 1.30.0-1ubuntu1+esm1 bionic
Affected pkg:deb/ubuntu/libnghttp2-dev?distro=xenial ubuntu libnghttp2-dev < 1.7.1-1ubuntu0.1~esm1 xenial
Affected pkg:deb/ubuntu/libnghttp2-dev?distro=focal ubuntu libnghttp2-dev < 1.40.0-1ubuntu0.1 focal
Affected pkg:deb/ubuntu/libnghttp2-dev?distro=bionic ubuntu libnghttp2-dev < 1.30.0-1ubuntu1+esm1 bionic
Affected pkg:deb/ubuntu/libnghttp2-14?distro=xenial ubuntu libnghttp2-14 < 1.7.1-1ubuntu0.1~esm1 xenial
Affected pkg:deb/ubuntu/libnghttp2-14?distro=focal ubuntu libnghttp2-14 < 1.40.0-1ubuntu0.1 focal
Affected pkg:deb/ubuntu/libnghttp2-14?distro=bionic ubuntu libnghttp2-14 < 1.30.0-1ubuntu1+esm1 bionic
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...