UBUNTU-CVE-2023-44487
Dashboard / Vulnerabilities / UBUNTU-CVE-2023-44487
UBUNTU-CVE-2023-44487
Summary:
Details: The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
References: https://ubuntu.com/security/CVE-2023-44487, https://blog.cloudflare.com/zero-day-rapid-reset-http2-record-breaking-ddos-attack/, https://blog.cloudflare.com/technical-breakdown-http2-rapid-reset-ddos-attack/, https://www.mail-archive.com/[email protected]/msg44134.html, https://www.nginx.com/blog/http-2-rapid-reset-attack-impacting-f5-nginx-products/, https://my.f5.com/manage/s/article/K000137106, https://mailman.nginx.org/pipermail/nginx-devel/2023-October/S36Q5HBXR7CAIMPLLPRSSSYR4PCMWILK.html, https://www.mail-archive.com/[email protected]/msg44134.html, https://devblogs.microsoft.com/dotnet/october-2023-updates/, https://ubuntu.com/security/notices/USN-6427-1, https://github.com/nghttp2/nghttp2/releases/tag/v1.57.0, https://groups.google.com/g/golang-announce/c/iNNxDTCjZvo, https://ubuntu.com/security/notices/USN-6427-2, https://ubuntu.com/security/notices/USN-6438-1, https://nodejs.org/en/blog/vulnerability/october-2023-security-releases, https://ubuntu.com/security/notices/USN-6505-1, https://ubuntu.com/security/notices/USN-6574-1, https://www.cve.org/CVERecord?id=CVE-2023-44487, https://ubuntu.com/security/notices/USN-6754-1, https://www.cisa.gov/known-exploited-vulnerabilities-catalog, https://ubuntu.com/security/notices/USN-6994-1, https://ubuntu.com/security/notices/USN-7067-1, https://ubuntu.com/security/notices/USN-7410-1, https://tomcat.apache.org/security-8.html, https://lists.apache.org/thread/5py8h42mxfsn8l1wy6o41xwhsjlsd87q, https://ubuntu.com/security/notices/USN-7469-1, https://ubuntu.com/security/notices/USN-7469-2, https://ubuntu.com/security/notices/USN-7469-3, https://ubuntu.com/security/notices/USN-7469-4, https://blog.powerdns.com/2024/02/16/powerdns-dnsdist-1.9.0-released, https://mailman.powerdns.com/pipermail/dnsdist/2023-October/001409.html, https://ubuntu.com/security/notices/USN-7892-1
Affected packages
Package
Name: nghttp2
Purl: pkg:deb/ubuntu/[email protected]~esm2?arch=source&distro=esm-apps/xenial
Affected ranges
Type: ECOSYSTEM
Events:
