[Forgot Password]
Login  Register Subscribe

30430

 
 

423868

 
 

247621

 
 

909

 
 

194512

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

CVE-2019-9515 -- libnetty-java, trafficserver, python-twisted, golang-google-grpc-dev, libgrpc-dev

ID: oval:org.secpod.oval:def:58063Date: (C)2019-10-10   (M)2023-12-20
Class: VULNERABILITYFamily: unix




This sends a stream of SETTINGS frames to the server. Since the RFC requires that the server reply with one acknowledgement per SETTINGS frame, an empty SETTINGS frame is almost equivalent in behavior to a ping. Depending on how efficiently this data is queued, this can consume excess CPU, memory, or both, potentially leading to a Denial-of-Service. Also known as "HTTP/2 Settings Flood".

Platform:
Ubuntu 16.04
Ubuntu 18.04
Product:
libnetty-java
trafficserver
python-twisted
golang-google-grpc-dev
libgrpc-dev
h2o
Reference:
CVE-2019-9515
CVE    1
CVE-2019-9515
CPE    8
cpe:/a:python:python-twisted
cpe:/o:ubuntu:ubuntu_linux:16.04
cpe:/o:ubuntu:ubuntu_linux:18.04
cpe:/a:apache:trafficserver
...

© SecPod Technologies