UBUNTU-CVE-2019-9513
Dashboard / Vulnerabilities / UBUNTU-CVE-2019-9513
UBUNTU-CVE-2019-9513
Summary:
Details: Some HTTP/2 implementations are vulnerable to resource loops, potentially leading to a denial of service. The attacker creates multiple request streams and continually shuffles the priority of the streams in a way that causes substantial churn to the priority tree. This can consume excess CPU.
References: https://ubuntu.com/security/CVE-2019-9513, https://github.com/Netflix/security-bulletins/blob/master/advisories/third-party/2019-002.md, https://ubuntu.com/security/notices/USN-4099-1, https://github.com/nodejs/node/pull/29133, https://github.com/nodejs/node/pull/29148, https://github.com/nodejs/node/pull/29152, https://www.cve.org/CVERecord?id=CVE-2019-9513, https://ubuntu.com/security/notices/USN-6754-1
Affected packages
Package
Name: nodejs
Purl: pkg:deb/ubuntu/[email protected]~dfsg2-2ubuntu1.2+esm2?arch=source&distro=esm-infra-legacy/trusty
Affected ranges
Type: ECOSYSTEM
Events:
