[Forgot Password]
Login  Register Subscribe

30430

 
 

423868

 
 

247862

 
 

909

 
 

194603

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

HTTP/2: large amount of data request leads to denial of service - CVE-2019-9511

ID: oval:org.secpod.oval:def:58202Date: (C)2019-10-10   (M)2024-04-17
Class: VULNERABILITYFamily: unix




Some HTTP/2 implementations are vulnerable to window size manipulation and stream prioritization manipulation, potentially leading to a denial of service. The attacker requests a large amount of data from a specified resource over multiple streams. They manipulate window size and stream priority to force the server to queue the data in 1-byte chunks. Depending on how efficiently this data is queued, this can consume excess CPU, memory, or both.

Platform:
Red Hat Enterprise Linux 8
Product:
nginx
nodejs
Reference:
CVE-2019-9511
CVE    1
CVE-2019-9511
CPE    3
cpe:/a:igor_sysoev:nginx
cpe:/o:redhat:enterprise_linux:8
cpe:/a:nodejs:nodejs

© SecPod Technologies