ALT-PU-2019-2601-1
Package libnghttp2 updated to version 1.39.2-alt1 for branch sisyphus in task 236978.
Closed vulnerabilities
BDU:2019-02994
Уязвимость реализации сетевого протокола HTTP/2 операционных систем Windows, сервера nginx, программной платформы Node.js, позволяющая нарушителю вызвать отказ в обслуживании
BDU:2019-02997
Уязвимость реализации сетевого протокола HTTP/2 операционных систем Windows, веб-сервера Apache Traffic Server, сетевых программных средств Envoy, программной платформы Node.js, позволяющая нарушителю вызвать отказ в обслуживании
BDU:2019-03782
Уязвимость реализации сетевого протокола HTTP/2 веб-сервера Apache HTTP Server, связанная с неконтролируемым расходом ресурса, позволяющая нарушителю вызвать отказ в обслуживании
Modified: 2024-11-21
CVE-2019-9511
Some HTTP/2 implementations are vulnerable to window size manipulation and stream prioritization manipulation, potentially leading to a denial of service. The attacker requests a large amount of data from a specified resource over multiple streams. They manipulate window size and stream priority to force the server to queue the data in 1-byte chunks. Depending on how efficiently this data is queued, this can consume excess CPU, memory, or both.
- openSUSE-SU-2019:2115
- openSUSE-SU-2019:2114
- openSUSE-SU-2019:2120
- openSUSE-SU-2019:2232
- openSUSE-SU-2019:2234
- openSUSE-SU-2019:2264
- RHSA-2019:2692
- RHSA-2019:2745
- RHSA-2019:2746
- RHSA-2019:2775
- RHSA-2019:2799
- RHSA-2019:2925
- RHSA-2019:2939
- RHSA-2019:2949
- RHSA-2019:2955
- RHSA-2019:2966
- RHSA-2019:3041
- RHSA-2019:3932
- RHSA-2019:3933
- RHSA-2019:3935
- RHSA-2019:4018
- RHSA-2019:4019
- RHSA-2019:4020
- RHSA-2019:4021
- https://github.com/Netflix/security-bulletins/blob/master/advisories/third-party/2019-002.md
- VU#605641
- https://kc.mcafee.com/corporate/index?page=content&id=SB10296
- FEDORA-2019-4427fd65be
- FEDORA-2019-8a437d5c2f
- FEDORA-2019-81985a8858
- FEDORA-2019-7a0b45fdc4
- FEDORA-2019-befd924cfe
- FEDORA-2019-63ba15cc83
- 20190822 [SECURITY] [DSA 4505-1] nginx security update
- 20190902 [SECURITY] [DSA 4511-1] nghttp2 security update
- https://security.netapp.com/advisory/ntap-20190823-0002/
- https://security.netapp.com/advisory/ntap-20190823-0005/
- https://support.f5.com/csp/article/K02591030
- https://support.f5.com/csp/article/K02591030?utm_source=f5support&%3Butm_medium=RSS
- USN-4099-1
- DSA-4505
- DSA-4511
- DSA-4669
- https://www.oracle.com/security-alerts/cpujan2021.html
- https://www.oracle.com/security-alerts/cpuoct2020.html
- https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html
- https://www.synology.com/security/advisory/Synology_SA_19_33
- openSUSE-SU-2019:2115
- https://www.synology.com/security/advisory/Synology_SA_19_33
- https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html
- https://www.oracle.com/security-alerts/cpuoct2020.html
- https://www.oracle.com/security-alerts/cpujan2021.html
- DSA-4669
- DSA-4511
- DSA-4505
- USN-4099-1
- https://support.f5.com/csp/article/K02591030?utm_source=f5support&%3Butm_medium=RSS
- https://support.f5.com/csp/article/K02591030
- https://security.netapp.com/advisory/ntap-20190823-0005/
- https://security.netapp.com/advisory/ntap-20190823-0002/
- 20190902 [SECURITY] [DSA 4511-1] nghttp2 security update
- 20190822 [SECURITY] [DSA 4505-1] nginx security update
- FEDORA-2019-63ba15cc83
- FEDORA-2019-befd924cfe
- FEDORA-2019-7a0b45fdc4
- FEDORA-2019-81985a8858
- FEDORA-2019-8a437d5c2f
- FEDORA-2019-4427fd65be
- https://kc.mcafee.com/corporate/index?page=content&id=SB10296
- VU#605641
- https://github.com/Netflix/security-bulletins/blob/master/advisories/third-party/2019-002.md
- RHSA-2019:4021
- RHSA-2019:4020
- RHSA-2019:4019
- RHSA-2019:4018
- RHSA-2019:3935
- RHSA-2019:3933
- RHSA-2019:3932
- RHSA-2019:3041
- RHSA-2019:2966
- RHSA-2019:2955
- RHSA-2019:2949
- RHSA-2019:2939
- RHSA-2019:2925
- RHSA-2019:2799
- RHSA-2019:2775
- RHSA-2019:2746
- RHSA-2019:2745
- RHSA-2019:2692
- openSUSE-SU-2019:2264
- openSUSE-SU-2019:2234
- openSUSE-SU-2019:2232
- openSUSE-SU-2019:2120
- openSUSE-SU-2019:2114
Modified: 2024-11-21
CVE-2019-9513
Some HTTP/2 implementations are vulnerable to resource loops, potentially leading to a denial of service. The attacker creates multiple request streams and continually shuffles the priority of the streams in a way that causes substantial churn to the priority tree. This can consume excess CPU.
- openSUSE-SU-2019:2115
- openSUSE-SU-2019:2114
- openSUSE-SU-2019:2120
- openSUSE-SU-2019:2232
- openSUSE-SU-2019:2234
- openSUSE-SU-2019:2264
- RHSA-2019:2692
- RHSA-2019:2745
- RHSA-2019:2746
- RHSA-2019:2775
- RHSA-2019:2799
- RHSA-2019:2925
- RHSA-2019:2939
- RHSA-2019:2949
- RHSA-2019:2955
- RHSA-2019:2966
- RHSA-2019:3041
- RHSA-2019:3932
- RHSA-2019:3933
- RHSA-2019:3935
- https://github.com/Netflix/security-bulletins/blob/master/advisories/third-party/2019-002.md
- VU#605641
- https://kc.mcafee.com/corporate/index?page=content&id=SB10296
- FEDORA-2019-6a2980de56
- FEDORA-2019-5a6a7bc12c
- FEDORA-2019-8a437d5c2f
- FEDORA-2019-81985a8858
- FEDORA-2019-7a0b45fdc4
- FEDORA-2019-befd924cfe
- 20190822 [SECURITY] [DSA 4505-1] nginx security update
- 20190902 [SECURITY] [DSA 4511-1] nghttp2 security update
- https://security.netapp.com/advisory/ntap-20190823-0002/
- https://security.netapp.com/advisory/ntap-20190823-0005/
- https://support.f5.com/csp/article/K02591030
- https://support.f5.com/csp/article/K02591030?utm_source=f5support&%3Butm_medium=RSS
- USN-4099-1
- DSA-4505
- DSA-4511
- DSA-4669
- https://www.oracle.com/security-alerts/cpujan2021.html
- https://www.oracle.com/security-alerts/cpuoct2020.html
- https://www.synology.com/security/advisory/Synology_SA_19_33
- openSUSE-SU-2019:2115
- https://www.synology.com/security/advisory/Synology_SA_19_33
- https://www.oracle.com/security-alerts/cpuoct2020.html
- https://www.oracle.com/security-alerts/cpujan2021.html
- DSA-4669
- DSA-4511
- DSA-4505
- USN-4099-1
- https://support.f5.com/csp/article/K02591030?utm_source=f5support&%3Butm_medium=RSS
- https://support.f5.com/csp/article/K02591030
- https://security.netapp.com/advisory/ntap-20190823-0005/
- https://security.netapp.com/advisory/ntap-20190823-0002/
- 20190902 [SECURITY] [DSA 4511-1] nghttp2 security update
- 20190822 [SECURITY] [DSA 4505-1] nginx security update
- FEDORA-2019-befd924cfe
- FEDORA-2019-7a0b45fdc4
- FEDORA-2019-81985a8858
- FEDORA-2019-8a437d5c2f
- FEDORA-2019-5a6a7bc12c
- FEDORA-2019-6a2980de56
- https://kc.mcafee.com/corporate/index?page=content&id=SB10296
- VU#605641
- https://github.com/Netflix/security-bulletins/blob/master/advisories/third-party/2019-002.md
- RHSA-2019:3935
- RHSA-2019:3933
- RHSA-2019:3932
- RHSA-2019:3041
- RHSA-2019:2966
- RHSA-2019:2955
- RHSA-2019:2949
- RHSA-2019:2939
- RHSA-2019:2925
- RHSA-2019:2799
- RHSA-2019:2775
- RHSA-2019:2746
- RHSA-2019:2745
- RHSA-2019:2692
- openSUSE-SU-2019:2264
- openSUSE-SU-2019:2234
- openSUSE-SU-2019:2232
- openSUSE-SU-2019:2120
- openSUSE-SU-2019:2114
Closed bugs
Уже есть 1.39.2