First published: Fri May 12 2017(Updated: )
H2O versions 2.0.3 and earlier and 2.1.0-beta2 and earlier allows remote attackers to cause a denial-of-service (DoS) via format string specifiers in a template file via fastcgi, mruby, proxy, redirect or reproxy.
Credit: vultures@jpcert.or.jp
Affected Software | Affected Version | How to fix |
---|---|---|
Dena H20 | >=2.0.0<=2.0.3 | |
Dena H20 | =2.1.0 | |
Dena H20 | =2.1.0-beta1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-4864 is classified as a denial-of-service vulnerability that can significantly impact the availability of the affected H2O server.
To mitigate CVE-2016-4864, upgrade H2O to version 2.0.4 or later, or 2.1.0-beta3 or later.
CVE-2016-4864 affects H2O versions 2.0.3 and earlier, as well as 2.1.0-beta2 and earlier.
CVE-2016-4864 allows remote attackers to perform denial-of-service attacks through malicious format string specifiers in template files.
Currently, there is no recommended workaround for CVE-2016-4864 other than upgrading to a secure version of H2O.