CVE-2018-6347: Input Validation
Published Dec 31, 2018
·Updated
An issue in the Proxygen handling of HTTP2 parsing of headers/trailers can lead to a denial-of-service attack. This affects Proxygen prior to v2018.12.31.00.
Affected Software
1 affected component
Proxygen Project Proxygen<2018.12.31.00
Remediation
Event History
Dec 31, 2018
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
DescriptionWeakness
Data Sourced
via NVD·10:29 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2018-6347?
CVE-2018-6347 has been classified as a denial-of-service (DoS) vulnerability.
2
How do I fix CVE-2018-6347?
To fix CVE-2018-6347, upgrade Proxygen to version 2018.12.31.00 or later.
3
What does CVE-2018-6347 affect?
CVE-2018-6347 affects versions of Proxygen prior to v2018.12.31.00.
4
What type of attack can CVE-2018-6347 cause?
CVE-2018-6347 can result in a denial-of-service attack due to improper handling of HTTP2 header parsing.
5
Is CVE-2018-6347 a critical vulnerability?
While CVE-2018-6347 can cause service disruption, it is primarily categorized as a denial-of-service vulnerability rather than critical.