CVE-2017-10868: Input Validation
Published Dec 22, 2017
·Updated
H2O version 2.2.2 and earlier allows remote attackers to cause a denial of service in the server via specially crafted HTTP/1 header.
Affected Software
1 affected component
Dena H2o<2.2.3
Event History
Dec 22, 2017
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID for H2O?
The vulnerability ID for H2O is CVE-2017-10868.
2
What is the severity level of CVE-2017-10868?
The severity level of CVE-2017-10868 is high with a value of 7.5.
3
How can remote attackers exploit CVE-2017-10868?
Remote attackers can exploit CVE-2017-10868 by causing a denial of service in the server using specially crafted HTTP/1 header.
4
Which versions of H2O are affected by CVE-2017-10868?
H2O version 2.2.2 and earlier are affected by CVE-2017-10868. Version 2.2.3 and later are not affected.
5
Is there a fix available for CVE-2017-10868?
Yes, upgrading to H2O version 2.2.3 or later is the recommended fix for CVE-2017-10868.