CVE-2019-9516

Severity CVSS v4.0:
Pending analysis
Type:
CWE-400 Uncontrolled Resource Consumption ('Resource Exhaustion')
Publication date:
13/08/2019
Last modified:
14/01/2025

Description

Some HTTP/2 implementations are vulnerable to a header leak, potentially leading to a denial of service. The attacker sends a stream of headers with a 0-length header name and 0-length header value, optionally Huffman encoded into 1-byte or greater headers. Some implementations allocate memory for these headers and keep the allocation alive until the session dies. This can consume excess memory.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:apple:swiftnio:*:*:*:*:*:*:*:* 1.0.0 (including) 1.4.0 (including)
cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:* 10.12 (including)
cpe:2.3:o:canonical:ubuntu_linux:*:*:*:*:*:*:*:* 14.04 (including)
cpe:2.3:a:apache:traffic_server:*:*:*:*:*:*:*:* 6.0.0 (including) 6.2.3 (including)
cpe:2.3:a:apache:traffic_server:*:*:*:*:*:*:*:* 7.0.0 (including) 7.1.6 (including)
cpe:2.3:a:apache:traffic_server:*:*:*:*:*:*:*:* 8.0.0 (including) 8.0.3 (including)
cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:19.04:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:30:*:*:*:*:*:*:*
cpe:2.3:a:synology:skynas:-:*:*:*:*:*:*:*
cpe:2.3:o:synology:diskstation_manager:6.2:*:*:*:*:*:*:*
cpe:2.3:o:synology:vs960hd_firmware:-:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools