CVE-2016-4864: High severity dena h20 vulnerability
H2O versions 2.0.3 and earlier and 2.1.0-beta2 and earlier allows remote attackers to cause a denial-of-service (DoS) via format string specifiers in a template file via fastcgi, mruby, proxy, redirect or reproxy.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2016-4864?
CVE-2016-4864 is classified as a denial-of-service vulnerability that can significantly impact the availability of the affected H2O server.
How do I fix CVE-2016-4864?
To mitigate CVE-2016-4864, upgrade H2O to version 2.0.4 or later, or 2.1.0-beta3 or later.
What versions are affected by CVE-2016-4864?
CVE-2016-4864 affects H2O versions 2.0.3 and earlier, as well as 2.1.0-beta2 and earlier.
What types of attacks are possible with CVE-2016-4864?
CVE-2016-4864 allows remote attackers to perform denial-of-service attacks through malicious format string specifiers in template files.
Is there a workaround for CVE-2016-4864?
Currently, there is no recommended workaround for CVE-2016-4864 other than upgrading to a secure version of H2O.