First published: Fri Dec 22 2017(Updated: )
H2O version 2.2.2 and earlier allows remote attackers to cause a denial of service in the server via specially crafted HTTP/1 header.
Credit: vultures@jpcert.or.jp
Affected Software | Affected Version | How to fix |
---|---|---|
Dena H2o | <2.2.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for H2O is CVE-2017-10868.
The severity level of CVE-2017-10868 is high with a value of 7.5.
Remote attackers can exploit CVE-2017-10868 by causing a denial of service in the server using specially crafted HTTP/1 header.
H2O version 2.2.2 and earlier are affected by CVE-2017-10868. Version 2.2.3 and later are not affected.
Yes, upgrading to H2O version 2.2.3 or later is the recommended fix for CVE-2017-10868.