First published: Tue Jan 12 2016(Updated: )
The idle stream handling in nghttp2 before 1.6.0 allows attackers to have unspecified impact via unknown vectors, aka a heap-use-after-free bug.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apple Mac OS X | <=10.11.3 | |
Nghttp2 Nghttp2 | <=1.5.0 | |
Apple iPhone OS | <=9.2.1 | |
Apple tvOS | <=9.1 | |
Apple watchOS | <=2.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.