CVE-2019-9514
high · 7.5Some HTTP/2 implementations are vulnerable to a reset flood, potentially leading to a denial of service. The attacker opens a number of streams and sends an invalid request over each stream that should solicit a stream of RST_STREAM frames from the peer. Depending on how the peer queues the RST_STREAM frames, this can consume excess memory, CPU, or both.
7.5
CVSS
82.8%
EPSS (exploit prob.)
100th
EPSS percentile
2019-08-13
Published
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Weaknesses
CWE-400CWE-770
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| apple | swiftnio | >= 1.0.0, <= 1.4.0 |
| apple | mac_os_x | >= 10.12 |
| canonical | ubuntu_linux | >= 14.04 |
| apache | traffic_server | >= 6.0.0, <= 6.2.3 |
| apache | traffic_server | >= 7.0.0, <= 7.1.6 |
| apache | traffic_server | >= 8.0.0, <= 8.0.3 |
| debian | debian_linux | 10.0 |
| canonical | ubuntu_linux | 16.04 |
| canonical | ubuntu_linux | 18.04 |
| canonical | ubuntu_linux | 19.04 |
| debian | debian_linux | 9.0 |
| debian | debian_linux | 10.0 |
| synology | skynas | all versions |
| synology | diskstation_manager | 6.2 |
| synology | vs960hd_firmware | all versions |
| synology | vs960hd | all versions |
| fedoraproject | fedora | 29 |
| fedoraproject | fedora | 30 |
| opensuse | leap | 15.0 |
| opensuse | leap | 15.1 |
| redhat | developer_tools | 1.0 |
| redhat | jboss_core_services | 1.0 |
| redhat | jboss_enterprise_application_platform | 7.2.0 |
| redhat | jboss_enterprise_application_platform | 7.3.0 |
| redhat | openshift_container_platform | 3.9 |
| redhat | openshift_container_platform | 3.10 |
| redhat | openshift_container_platform | 3.11 |
| redhat | openshift_container_platform | 4.1 |
| redhat | openshift_container_platform | 4.2 |
| redhat | openshift_service_mesh | 1.0 |
| redhat | openstack | 14 |
| redhat | quay | 3.0.0 |
| redhat | single_sign-on | 7.3 |
| redhat | software_collections | 1.0 |
| redhat | enterprise_linux | 8.0 |
| redhat | enterprise_linux_eus | 8.1 |
| redhat | enterprise_linux_server | 7.0 |
| redhat | enterprise_linux_workstation | 7.0 |
| oracle | graalvm | 19.2.0 |
| mcafee | web_gateway | >= 7.7.2.0, < 7.7.2.24 |
Check a specific version with /api/v1/cve/match.
References
- http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00076.html
- http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00002.html
- http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00011.html
- http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00021.html
- http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00031.html
- http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00032.html
- http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00038.html
- http://seclists.org/fulldisclosure/2019/Aug/16
- http://www.openwall.com/lists/oss-security/2019/08/20/1
- http://www.openwall.com/lists/oss-security/2023/10/18/8
- https://access.redhat.com/errata/RHSA-2019:2594
- https://access.redhat.com/errata/RHSA-2019:2661
- https://access.redhat.com/errata/RHSA-2019:2682
- https://access.redhat.com/errata/RHSA-2019:2690
- https://access.redhat.com/errata/RHSA-2019:2726
- https://access.redhat.com/errata/RHSA-2019:2766
- https://access.redhat.com/errata/RHSA-2019:2769
- https://access.redhat.com/errata/RHSA-2019:2796
- https://access.redhat.com/errata/RHSA-2019:2861
- https://access.redhat.com/errata/RHSA-2019:2925
- https://access.redhat.com/errata/RHSA-2019:2939
- https://access.redhat.com/errata/RHSA-2019:2955
- https://access.redhat.com/errata/RHSA-2019:2966
- https://access.redhat.com/errata/RHSA-2019:3131
- https://access.redhat.com/errata/RHSA-2019:3245
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2019-9514