First published: Thu Aug 01 2019(Updated: )
A flaw was found in HTTP/2. Using frames with an empty payload, a flood could occur that results in excessive CPU usage and starvation of other clients. The highest threat from this vulnerability is to system availability.
Credit: cret@cert.org cret@cert.org
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/rh-nodejs10 | <0:3.2-3.el7 | 0:3.2-3.el7 |
redhat/rh-nodejs10-nodejs | <0:10.16.3-3.el7 | 0:10.16.3-3.el7 |
redhat/rh-nodejs8 | <0:3.0-5.el7 | 0:3.0-5.el7 |
redhat/rh-nodejs8-nodejs | <0:8.16.1-2.el7 | 0:8.16.1-2.el7 |
redhat/envoy | <1.11.1 | 1.11.1 |
redhat/Nodejs | <8.16.1 | 8.16.1 |
redhat/Nodejs | <10.16.3 | 10.16.3 |
redhat/Nodejs | <12.8.1 | 12.8.1 |
redhat/undertow | <2.0.26. | 2.0.26. |
All of | ||
Apple Swiftnio | >=1.0.0<=1.4.0 | |
Any of | ||
Apple Mac OS X | >=10.12 | |
Canonical Ubuntu Linux | >=14.04 | |
Apache Traffic Server | >=6.0.0<=6.2.3 | |
Apache Traffic Server | >=7.0.0<=7.1.6 | |
Apache Traffic Server | >=8.0.0<=8.0.3 | |
Canonical Ubuntu Linux | =16.04 | |
Canonical Ubuntu Linux | =18.04 | |
Canonical Ubuntu Linux | =19.04 | |
Debian Debian Linux | =9.0 | |
Debian Debian Linux | =10.0 | |
Synology DiskStation Manager | =6.2 | |
Synology Skynas | ||
All of | ||
Synology Vs960hd Firmware | ||
Synology Vs960hd | ||
Fedoraproject Fedora | =29 | |
Fedoraproject Fedora | =30 | |
openSUSE Leap | =15.0 | |
openSUSE Leap | =15.1 | |
Redhat Jboss Core Services | =1.0 | |
Redhat Jboss Enterprise Application Platform | =7.2.0 | |
Redhat Jboss Enterprise Application Platform | =7.3.0 | |
Redhat Openshift Service Mesh | =1.0 | |
Redhat Quay | =3.0.0 | |
Redhat Software Collections | =1.0 | |
Redhat Enterprise Linux | =8.0 | |
Oracle GraalVM | =19.2.0 | |
McAfee Web Gateway | >=7.7.2.0<7.7.2.24 | |
McAfee Web Gateway | >=7.8.2.0<7.8.2.13 | |
McAfee Web Gateway | >=8.1.0<8.2.0 | |
Nodejs Node.js | >=8.0.0<=8.8.1 | |
Nodejs Node.js | >=8.9.0<8.16.1 | |
Nodejs Node.js | >=10.0.0<=10.12.0 | |
Nodejs Node.js | >=10.13.0<10.16.3 | |
Nodejs Node.js | >=12.0.0<12.8.1 | |
Apple Swiftnio | >=1.0.0<=1.4.0 | |
Apple Mac OS X | >=10.12 | |
Canonical Ubuntu Linux | >=14.04 | |
Synology Vs960hd Firmware | ||
Synology Vs960hd | ||
debian/trafficserver | 8.1.10+ds-1~deb11u1 8.1.11+ds-0+deb11u1 9.2.4+ds-0+deb12u1 9.2.5+ds-0+deb12u1 9.2.5+ds-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
CVE-2019-9518 is a vulnerability in HTTP/2 that allows for a flood of empty frames, potentially leading to a denial of service.
CVE-2019-9518 has a severity level of high, with a severity value of 7.
The affected software includes rh-nodejs10, rh-nodejs10-nodejs, rh-nodejs8, rh-nodejs8-nodejs, envoy, Nodejs, undertow, netty, and trafficserver.
To fix CVE-2019-9518, ensure that you have the latest versions of the affected software installed, as specified in the Remediation section of the references.
You can find more information about CVE-2019-9518 in the references provided.