CVE-2016-4817
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
19/06/2016
Last modified:
12/04/2025
Description
lib/http2/connection.c in H2O before 1.7.3 and 2.x before 2.0.0-beta5 mishandles HTTP/2 disconnection, which allows remote attackers to cause a denial of service (use-after-free and application crash) or possibly execute arbitrary code via a crafted packet.
Impact
Base Score 3.x
7.50
Severity 3.x
HIGH
Base Score 2.0
5.00
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:dena:h2o:*:*:*:*:*:*:*:* | 1.7.2 (including) | |
| cpe:2.3:a:dena:h2o:*:beta4:*:*:*:*:*:* | 2.0.0 (including) |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://jvn.jp/en/jp/JVN87859762/index.html
- http://jvndb.jvn.jp/jvndb/JVNDB-2016-000091
- https://github.com/h2o/h2o/commit/1c0808d580da09fdec5a9a74ff09e103ea058dd4
- https://github.com/h2o/h2o/pull/920
- http://jvn.jp/en/jp/JVN87859762/index.html
- http://jvndb.jvn.jp/jvndb/JVNDB-2016-000091
- https://github.com/h2o/h2o/commit/1c0808d580da09fdec5a9a74ff09e103ea058dd4
- https://github.com/h2o/h2o/pull/920



