CVE-2018-6346: High severity proxygen vulnerability
Published Dec 31, 2018
·Updated
A potential denial-of-service issue in the Proxygen handling of invalid HTTP2 priority settings (specifically a circular dependency). This affects Proxygen prior to v2018.12.31.00.
Affected Software
1 affected component
Proxygen Project Proxygen<2018.12.31.00
Remediation
Event History
Dec 31, 2018
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
DescriptionWeakness
Data Sourced
via NVD·10:29 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2018-6346?
CVE-2018-6346 is classified as a potential denial-of-service vulnerability.
2
How do I fix CVE-2018-6346?
To mitigate CVE-2018-6346, update Proxygen to version 2018.12.31.00 or later.
3
What software is affected by CVE-2018-6346?
CVE-2018-6346 affects Proxygen versions prior to 2018.12.31.00.
4
What type of issue is CVE-2018-6346?
CVE-2018-6346 is a denial-of-service issue related to invalid HTTP2 priority settings.
5
Can CVE-2018-6346 lead to service disruptions?
Yes, CVE-2018-6346 can lead to service disruptions due to denial-of-service conditions.