imPC@ndo EN

Tracker / CVE-2018-16844

CVE-2018-16844

Alta 7.5

nginx before versions 1.15.6 and 1.14.1 has a vulnerability in the implementation of HTTP/2 that can allow for excessive CPU usage. This issue affects nginx compiled with the ngx_http_v2_module (not compiled by default) if the 'http2' option of the 'listen' directive is used in a configuration file.

Prodotti e versioni affette

apple xcode · … → 13.0
canonical ubuntu_linux
debian debian_linux
f5 nginx · 1.15.0 → 1.15.6
f5 nginx · 1.9.5 → 1.14.1

Analisi

Questa pagina non è ancora indicizzabile.Finché non contiene un’analisi originale — cosa espone davvero, come verificare in due minuti se un sistema è stato toccato, cosa fare se lo è stato — la pagina resta noindex. È il database a deciderlo, non il modello di pagina.

Riferimenti