First published: Tue Sep 17 2019(Updated: )
Skydive is an open source real-time network topology and protocols analyzer.<br>Security Fix(es):<br><li> HTTP/2: flood using PING frames results in unbounded memory growth (CVE-2019-9512)</li> <li> HTTP/2: flood using HEADERS frames results in unbounded memory growth (CVE-2019-9514)</li> <li> HTTP/2: flood using SETTINGS frames results in unbounded memory growth (CVE-2019-9515)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/skydive | <0.20.5-2.el7 | 0.20.5-2.el7 |
redhat/skydive-agent | <0.20.5-2.el7 | 0.20.5-2.el7 |
redhat/skydive-analyzer | <0.20.5-2.el7 | 0.20.5-2.el7 |
redhat/skydive-ansible | <0.20.5-2.el7 | 0.20.5-2.el7 |
redhat/skydive-debuginfo | <0.20.5-2.el7 | 0.20.5-2.el7 |
redhat/skydive-selinux | <0.20.5-2.el7 | 0.20.5-2.el7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.