First published: Wed Apr 30 2025(Updated: )
USN-7469-1 fixed a vulnerability in Apache Traffic Server. This update provides the corresponding updates for H2O. Original advisory details: It was discovered that Apache Traffic Server exhibited poor server resource management in its HTTP/2 protocol. An attacker could possibly use this issue to cause Apache Traffic Server to crash, resulting in a denial of service.
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
ubuntu/h2o | <2.2.4+dfsg-1ubuntu0.1~esm2 | 2.2.4+dfsg-1ubuntu0.1~esm2 |
Ubuntu | =18.04 | |
All of | ||
ubuntu/libh2o0.13 | <2.2.4+dfsg-1ubuntu0.1~esm2 | 2.2.4+dfsg-1ubuntu0.1~esm2 |
Ubuntu | =18.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of USN-7469-4 is considered important due to the potential impact on resource management in Apache Traffic Server's HTTP/2 protocol.
To fix USN-7469-4, ensure that you update to the latest version of H2O, specifically 2.2.4+dfsg-1ubuntu0.1~esm2 for Ubuntu 18.04.
USN-7469-4 affects the H2O package and libh2o0.13 on Ubuntu 18.04.
USN-7469-4 addresses a vulnerability related to poor server resource management in Apache Traffic Server's implementation of the HTTP/2 protocol.
Yes, USN-7469-4 is a continuation of fixes provided in USN-7469-1.