UBUNTU-CVE-2019-9516
Dashboard / Vulnerabilities / UBUNTU-CVE-2019-9516
UBUNTU-CVE-2019-9516
Summary:
Details: Some HTTP/2 implementations are vulnerable to a header leak, potentially leading to a denial of service. The attacker sends a stream of headers with a 0-length header name and 0-length header value, optionally Huffman encoded into 1-byte or greater headers. Some implementations allocate memory for these headers and keep the allocation alive until the session dies. This can consume excess memory.
References: https://ubuntu.com/security/CVE-2019-9516, https://github.com/Netflix/security-bulletins/blob/master/advisories/third-party/2019-002.md, https://ubuntu.com/security/notices/USN-4099-1, https://www.cve.org/CVERecord?id=CVE-2019-9516
Affected packages
Package
Name: nginx
Purl: pkg:deb/ubuntu/[email protected]?arch=source&distro=xenial
Affected ranges
Type: ECOSYSTEM
Events:
