ALSA-2019:2799
Dashboard / Vulnerabilities / ALSA-2019:2799
ALSA-2019:2799
Summary: Important: nginx:1.14 security update
Details: Nginx is a web server and a reverse proxy server for HTTP, SMTP, POP3 (Post Office Protocol 3) and IMAP protocols, with a focus on high concurrency, performance and low memory usage. Security Fix(es): * HTTP/2: large amount of data request leads to denial of service (CVE-2019-9511) * HTTP/2: flood using PRIORITY frames resulting in excessive resource consumption (CVE-2019-9513) * HTTP/2: 0-length headers leads to denial of service (CVE-2019-9516) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
References: https://errata.almalinux.org/8/ALSA-2019-2799.html, https://vulners.com/cve/CVE-2019-9511, https://vulners.com/cve/CVE-2019-9513, https://vulners.com/cve/CVE-2019-9516
Affected packages
Package
Name: nginx
Purl: pkg:rpm/almalinux/nginx
Affected ranges
Type: ECOSYSTEM
Events:
