[Forgot Password]
Login  Register Subscribe

30430

 
 

423868

 
 

247768

 
 

909

 
 

194555

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

CVE-2019-9514 -- libnetty-java, trafficserver, python-twisted, golang-google-grpc-dev, libgrpc-dev

ID: oval:org.secpod.oval:def:58060Date: (C)2019-10-10   (M)2023-12-20
Class: VULNERABILITYFamily: unix




This opens a number of streams and sends an invalid request over each stream that should solicit a stream of RST_STREAM frames from the peer. Depending on how the servers queue the RST_STREAM frames, this can consume excess memory, CPU, or both, potentially leading to a Denial-of-Service. Also known as "HTTP/2 Reset Flood".

Platform:
Ubuntu 16.04
Ubuntu 19.04
Ubuntu 18.04
Product:
libnetty-java
trafficserver
python-twisted
golang-google-grpc-dev
libgrpc-dev
Reference:
CVE-2019-9514
CVE    1
CVE-2019-9514
CPE    8
cpe:/a:python:python-twisted
cpe:/o:ubuntu:ubuntu_linux:16.04
cpe:/o:ubuntu:ubuntu_linux:18.04
cpe:/a:apache:trafficserver
...

© SecPod Technologies