[USN-6505-1] nghttp2 vulnerability

Severity High
Affected Packages 28
CVEs 1

nghttp2 could be made to consume resources if it received specially crafted network traffic.

It was discovered that nghttp2 incorrectly handled request cancellation. A
remote attacker could possibly use this issue to cause nghttp2 to consume
resources, leading to a denial of service.

Package Affected Version
pkg:deb/ubuntu/nghttp2?distro=mantic < 1.55.1-1ubuntu0.1
pkg:deb/ubuntu/nghttp2?distro=lunar < 1.52.0-1ubuntu0.1
pkg:deb/ubuntu/nghttp2?distro=jammy < 1.43.0-1ubuntu0.1
pkg:deb/ubuntu/nghttp2?distro=focal < 1.40.0-1ubuntu0.2
pkg:deb/ubuntu/nghttp2-server?distro=mantic < 1.55.1-1ubuntu0.1
pkg:deb/ubuntu/nghttp2-server?distro=lunar < 1.52.0-1ubuntu0.1
pkg:deb/ubuntu/nghttp2-server?distro=jammy < 1.43.0-1ubuntu0.1
pkg:deb/ubuntu/nghttp2-server?distro=focal < 1.40.0-1ubuntu0.2
pkg:deb/ubuntu/nghttp2-proxy?distro=mantic < 1.55.1-1ubuntu0.1
pkg:deb/ubuntu/nghttp2-proxy?distro=lunar < 1.52.0-1ubuntu0.1
pkg:deb/ubuntu/nghttp2-proxy?distro=jammy < 1.43.0-1ubuntu0.1
pkg:deb/ubuntu/nghttp2-proxy?distro=focal < 1.40.0-1ubuntu0.2
pkg:deb/ubuntu/nghttp2-client?distro=mantic < 1.55.1-1ubuntu0.1
pkg:deb/ubuntu/nghttp2-client?distro=lunar < 1.52.0-1ubuntu0.1
pkg:deb/ubuntu/nghttp2-client?distro=jammy < 1.43.0-1ubuntu0.1
pkg:deb/ubuntu/nghttp2-client?distro=focal < 1.40.0-1ubuntu0.2
pkg:deb/ubuntu/libnghttp2-doc?distro=mantic < 1.55.1-1ubuntu0.1
pkg:deb/ubuntu/libnghttp2-doc?distro=lunar < 1.52.0-1ubuntu0.1
pkg:deb/ubuntu/libnghttp2-doc?distro=jammy < 1.43.0-1ubuntu0.1
pkg:deb/ubuntu/libnghttp2-doc?distro=focal < 1.40.0-1ubuntu0.2
pkg:deb/ubuntu/libnghttp2-dev?distro=mantic < 1.55.1-1ubuntu0.1
pkg:deb/ubuntu/libnghttp2-dev?distro=lunar < 1.52.0-1ubuntu0.1
pkg:deb/ubuntu/libnghttp2-dev?distro=jammy < 1.43.0-1ubuntu0.1
pkg:deb/ubuntu/libnghttp2-dev?distro=focal < 1.40.0-1ubuntu0.2
pkg:deb/ubuntu/libnghttp2-14?distro=mantic < 1.55.1-1ubuntu0.1
pkg:deb/ubuntu/libnghttp2-14?distro=lunar < 1.52.0-1ubuntu0.1
pkg:deb/ubuntu/libnghttp2-14?distro=jammy < 1.43.0-1ubuntu0.1
pkg:deb/ubuntu/libnghttp2-14?distro=focal < 1.40.0-1ubuntu0.2
ID
USN-6505-1
Severity
high
Severity from
CVE-2023-44487
URL
https://ubuntu.com/security/notices/USN-6505-1
Published
2023-11-22T14:45:49
(10 months ago)
Modified
2023-11-22T14:45:49
(10 months ago)
Other Advisories
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:deb/ubuntu/nghttp2?distro=mantic ubuntu nghttp2 < 1.55.1-1ubuntu0.1 mantic
Affected pkg:deb/ubuntu/nghttp2?distro=lunar ubuntu nghttp2 < 1.52.0-1ubuntu0.1 lunar
Affected pkg:deb/ubuntu/nghttp2?distro=jammy ubuntu nghttp2 < 1.43.0-1ubuntu0.1 jammy
Affected pkg:deb/ubuntu/nghttp2?distro=focal ubuntu nghttp2 < 1.40.0-1ubuntu0.2 focal
Affected pkg:deb/ubuntu/nghttp2-server?distro=mantic ubuntu nghttp2-server < 1.55.1-1ubuntu0.1 mantic
Affected pkg:deb/ubuntu/nghttp2-server?distro=lunar ubuntu nghttp2-server < 1.52.0-1ubuntu0.1 lunar
Affected pkg:deb/ubuntu/nghttp2-server?distro=jammy ubuntu nghttp2-server < 1.43.0-1ubuntu0.1 jammy
Affected pkg:deb/ubuntu/nghttp2-server?distro=focal ubuntu nghttp2-server < 1.40.0-1ubuntu0.2 focal
Affected pkg:deb/ubuntu/nghttp2-proxy?distro=mantic ubuntu nghttp2-proxy < 1.55.1-1ubuntu0.1 mantic
Affected pkg:deb/ubuntu/nghttp2-proxy?distro=lunar ubuntu nghttp2-proxy < 1.52.0-1ubuntu0.1 lunar
Affected pkg:deb/ubuntu/nghttp2-proxy?distro=jammy ubuntu nghttp2-proxy < 1.43.0-1ubuntu0.1 jammy
Affected pkg:deb/ubuntu/nghttp2-proxy?distro=focal ubuntu nghttp2-proxy < 1.40.0-1ubuntu0.2 focal
Affected pkg:deb/ubuntu/nghttp2-client?distro=mantic ubuntu nghttp2-client < 1.55.1-1ubuntu0.1 mantic
Affected pkg:deb/ubuntu/nghttp2-client?distro=lunar ubuntu nghttp2-client < 1.52.0-1ubuntu0.1 lunar
Affected pkg:deb/ubuntu/nghttp2-client?distro=jammy ubuntu nghttp2-client < 1.43.0-1ubuntu0.1 jammy
Affected pkg:deb/ubuntu/nghttp2-client?distro=focal ubuntu nghttp2-client < 1.40.0-1ubuntu0.2 focal
Affected pkg:deb/ubuntu/libnghttp2-doc?distro=mantic ubuntu libnghttp2-doc < 1.55.1-1ubuntu0.1 mantic
Affected pkg:deb/ubuntu/libnghttp2-doc?distro=lunar ubuntu libnghttp2-doc < 1.52.0-1ubuntu0.1 lunar
Affected pkg:deb/ubuntu/libnghttp2-doc?distro=jammy ubuntu libnghttp2-doc < 1.43.0-1ubuntu0.1 jammy
Affected pkg:deb/ubuntu/libnghttp2-doc?distro=focal ubuntu libnghttp2-doc < 1.40.0-1ubuntu0.2 focal
Affected pkg:deb/ubuntu/libnghttp2-dev?distro=mantic ubuntu libnghttp2-dev < 1.55.1-1ubuntu0.1 mantic
Affected pkg:deb/ubuntu/libnghttp2-dev?distro=lunar ubuntu libnghttp2-dev < 1.52.0-1ubuntu0.1 lunar
Affected pkg:deb/ubuntu/libnghttp2-dev?distro=jammy ubuntu libnghttp2-dev < 1.43.0-1ubuntu0.1 jammy
Affected pkg:deb/ubuntu/libnghttp2-dev?distro=focal ubuntu libnghttp2-dev < 1.40.0-1ubuntu0.2 focal
Affected pkg:deb/ubuntu/libnghttp2-14?distro=mantic ubuntu libnghttp2-14 < 1.55.1-1ubuntu0.1 mantic
Affected pkg:deb/ubuntu/libnghttp2-14?distro=lunar ubuntu libnghttp2-14 < 1.52.0-1ubuntu0.1 lunar
Affected pkg:deb/ubuntu/libnghttp2-14?distro=jammy ubuntu libnghttp2-14 < 1.43.0-1ubuntu0.1 jammy
Affected pkg:deb/ubuntu/libnghttp2-14?distro=focal ubuntu libnghttp2-14 < 1.40.0-1ubuntu0.2 focal
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...