First published: Mon Dec 31 2018(Updated: )
An issue in the Proxygen handling of HTTP2 parsing of headers/trailers can lead to a denial-of-service attack. This affects Proxygen prior to v2018.12.31.00.
Credit: cve-assign@fb.com
Affected Software | Affected Version | How to fix |
---|---|---|
Proxygen | <2018.12.31.00 | |
<2018.12.31.00 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-6347 has been classified as a denial-of-service (DoS) vulnerability.
To fix CVE-2018-6347, upgrade Proxygen to version 2018.12.31.00 or later.
CVE-2018-6347 affects versions of Proxygen prior to v2018.12.31.00.
CVE-2018-6347 can result in a denial-of-service attack due to improper handling of HTTP2 header parsing.
While CVE-2018-6347 can cause service disruption, it is primarily categorized as a denial-of-service vulnerability rather than critical.