UBUNTU-CVE-2019-9514
Dashboard / Vulnerabilities / UBUNTU-CVE-2019-9514
UBUNTU-CVE-2019-9514
Summary:
Details: Some HTTP/2 implementations are vulnerable to a reset flood, potentially leading to a denial of service. The attacker opens a number of streams and sends an invalid request over each stream that should solicit a stream of RST_STREAM frames from the peer. Depending on how the peer queues the RST_STREAM frames, this can consume excess memory, CPU, or both.
References: https://ubuntu.com/security/CVE-2019-9514, https://github.com/Netflix/security-bulletins/blob/master/advisories/third-party/2019-002.md, https://netty.io/news/2019/08/13/4-1-39-Final.html, http://blog.kazuhooku.com/2019/08/h2o-version-226-230-beta2-released.html, https://github.com/netty/netty/pull/9460, https://labs.twistedmatrix.com/2019/11/twisted-19100-released.html, https://ubuntu.com/security/notices/USN-4308-1, https://ubuntu.com/security/notices/USN-4866-1, https://github.com/nodejs/node/pull/29133, https://github.com/nodejs/node/pull/29148, https://github.com/nodejs/node/pull/29152, https://www.cve.org/CVERecord?id=CVE-2019-9514
Affected packages
Package
Name: golang-1.10
Purl: pkg:deb/ubuntu/golang-1.10?arch=source&distro=trusty
Affected ranges
Type: ECOSYSTEM
Events:
