CVE-2016-4817: Use After Free
Published Jun 19, 2016
·Updated
lib/http2/connection.c in H2O before 1.7.3 and 2.x before 2.0.0-beta5 mishandles HTTP/2 disconnection, which allows remote attackers to cause a denial of service (use-after-free and application crash) or possibly execute arbitrary code via a crafted packet.
Affected Software
2 affected components
Dena H2o<=1.7.2
Dena H2o<=2.0.0
Event History
Jun 19, 2016
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-4817?
CVE-2016-4817 has a high severity rating due to its potential to cause denial of service or execute arbitrary code.
2
How do I fix CVE-2016-4817?
To fix CVE-2016-4817, update H2O to version 1.7.3 or 2.0.0-beta5 or later.
3
What software is affected by CVE-2016-4817?
CVE-2016-4817 affects H2O versions prior to 1.7.3 and beta4 versions of 2.0.0.
4
What type of vulnerability is CVE-2016-4817?
CVE-2016-4817 is a use-after-free vulnerability that leads to potential application crashes.
5
Can CVE-2016-4817 be exploited remotely?
Yes, CVE-2016-4817 can be exploited remotely by attackers via specially crafted HTTP/2 packets.