First published: Fri Dec 22 2017(Updated: )
H2O version 2.2.3 and earlier allows remote attackers to cause a denial of service in the server via specially crafted HTTP/2 header.
Credit: vultures@jpcert.or.jp
Affected Software | Affected Version | How to fix |
---|---|---|
Dena H2o | <=2.2.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2017-10908 is high with a CVSS score of 7.5.
CVE-2017-10908 allows remote attackers to cause a denial of service in H2O version 2.2.3 and earlier by sending specially crafted HTTP/2 headers.
H2O version 2.2.3 and earlier on Microsoft Windows Server 2022 are affected by CVE-2017-10908.
Updating to a version of H2O later than 2.2.3 will fix CVE-2017-10908.
You can find more information about CVE-2017-10908 on the GitHub issue and JVN pages.