Tracker / CVE-2019-9512
CVE-2019-9512
Alta 7.5
Some HTTP/2 implementations are vulnerable to ping floods, potentially leading to a denial of service. The attacker sends continual pings to an HTTP/2 peer, causing the peer to build an internal queue of responses. Depending on how efficiently this data is queued, this can consume excess CPU, memory, or both.
Prodotti e versioni affette
| apache | traffic_server · 6.0.0 → 6.2.3 |
|---|---|
| apache | traffic_server · 7.0.0 → 7.1.6 |
| apache | traffic_server · 8.0.0 → 8.0.3 |
| apple | swiftnio · 1.0.0 → 1.4.0 |
| debian | debian_linux |
| nodejs | node.js · 10.0.0 → 10.12.0 |
| nodejs | node.js · 10.13.0 → 10.16.3 |
| nodejs | node.js · 12.0.0 → 12.8.1 |
| nodejs | node.js · 8.0.0 → 8.8.1 |
| nodejs | node.js · 8.9.0 → 8.16.1 |
Analisi
Questa pagina non è ancora indicizzabile.Finché non contiene un’analisi originale — cosa espone davvero, come verificare in due minuti se un sistema è stato toccato, cosa fare se lo è stato — la pagina resta noindex. È il database a deciderlo, non il modello di pagina.