Vulnerability CVE-2019-9516: Information

Description

Some HTTP/2 implementations are vulnerable to a header leak, potentially leading to a denial of service. The attacker sends a stream of headers with a 0-length header name and 0-length header value, optionally Huffman encoded into 1-byte or greater headers. Some implementations allocate memory for these headers and keep the allocation alive until the session dies. This can consume excess memory.

Severity: MEDIUM (6.5) Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Published: Aug. 14, 2019
Modified: Nov. 7, 2023
Error type identifier: CWE-770

Fixed packages

References to Advisories, Solutions, and Tools

Hyperlink
Resource
VU#605641
  • Third Party Advisory
  • US Government Resource
https://github.com/Netflix/security-bulletins/blob/master/advisories/third-party/2019-002.md
  • Third Party Advisory
20190814 APPLE-SA-2019-08-13-5 SwiftNIO HTTP/2 1.5.0
  • Mailing List
  • Third Party Advisory
USN-4099-1
  • Third Party Advisory
20190816 APPLE-SA-2019-08-13-5 SwiftNIO HTTP/2 1.5.0
  • Mailing List
  • Third Party Advisory
https://www.synology.com/security/advisory/Synology_SA_19_33
  • Third Party Advisory
https://support.f5.com/csp/article/K02591030
  • Third Party Advisory
20190822 [SECURITY] [DSA 4505-1] nginx security update
  • Mailing List
  • Third Party Advisory
DSA-4505
  • Third Party Advisory
https://security.netapp.com/advisory/ntap-20190823-0005/
  • Third Party Advisory
https://security.netapp.com/advisory/ntap-20190823-0002/
  • Third Party Advisory
openSUSE-SU-2019:2120
  • Mailing List
  • Third Party Advisory
openSUSE-SU-2019:2114
  • Mailing List
  • Third Party Advisory
openSUSE-SU-2019:2115
  • Mailing List
  • Third Party Advisory
https://kc.mcafee.com/corporate/index?page=content&id=SB10296
  • Third Party Advisory
RHSA-2019:2746
  • Third Party Advisory
RHSA-2019:2745
  • Third Party Advisory
RHSA-2019:2775
  • Third Party Advisory
RHSA-2019:2799
  • Third Party Advisory
RHSA-2019:2925
  • Third Party Advisory
RHSA-2019:2939
  • Third Party Advisory
RHSA-2019:2946
  • Third Party Advisory
RHSA-2019:2950
  • Third Party Advisory
RHSA-2019:2955
  • Third Party Advisory
RHSA-2019:2966
  • Third Party Advisory
openSUSE-SU-2019:2264
  • Mailing List
  • Third Party Advisory
RHSA-2019:3935
  • Third Party Advisory
RHSA-2019:3933
  • Third Party Advisory
RHSA-2019:3932
  • Third Party Advisory
FEDORA-2019-befd924cfe
    FEDORA-2019-5a6a7bc12c
      FEDORA-2019-6a2980de56
        FEDORA-2019-4427fd65be
          FEDORA-2019-63ba15cc83
            FEDORA-2019-7a0b45fdc4
              https://support.f5.com/csp/article/K02591030?utm_source=f5support&amp%3Butm_medium=RSS
                FEDORA-2021-d5b2c18fe6
                    1. Configuration 1

                      cpe:2.3:a:apple:swiftnio:*:*:*:*:*:*:*:*

                      Running on/with:
                      cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:*

                      Running on/with:
                      cpe:2.3:o:canonical:ubuntu_linux:*:*:*:*:*:*:*:*

                      Configuration 2

                      cpe:2.3:a:apache:traffic_server:*:*:*:*:*:*:*:*
                      Start including
                      8.0.0
                      End including
                      8.0.3

                      cpe:2.3:a:apache:traffic_server:*:*:*:*:*:*:*:*
                      Start including
                      7.0.0
                      End including
                      7.1.6

                      cpe:2.3:a:apache:traffic_server:*:*:*:*:*:*:*:*
                      Start including
                      6.0.0
                      End including
                      6.2.3

                      Configuration 3

                      cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:*

                      cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*

                      cpe:2.3:o:canonical:ubuntu_linux:19.04:*:*:*:*:*:*:*

                      Configuration 4

                      cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*

                      cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*

                      cpe:2.3:o:fedoraproject:fedora:30:*:*:*:*:*:*:*

                      Configuration 5

                      cpe:2.3:a:synology:skynas:-:*:*:*:*:*:*:*

                      cpe:2.3:a:synology:diskstation_manager:6.2:*:*:*:*:*:*:*

                      Configuration 6

                      cpe:2.3:o:synology:vs960hd_firmware:-:*:*:*:*:*:*:*

                      Running on/with:
                      cpe:2.3:h:synology:vs960hd:-:*:*:*:*:*:*:*

                      Configuration 7

                      cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*

                      cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*

                      Configuration 8

                      cpe:2.3:o:fedoraproject:fedora:29:*:*:*:*:*:*:*

                      cpe:2.3:o:fedoraproject:fedora:30:*:*:*:*:*:*:*

                      cpe:2.3:o:fedoraproject:fedora:32:*:*:*:*:*:*:*

                      Configuration 9

                      cpe:2.3:o:opensuse:leap:15.0:*:*:*:*:*:*:*

                      cpe:2.3:o:opensuse:leap:15.1:*:*:*:*:*:*:*

                      Configuration 10

                      cpe:2.3:a:redhat:software_collections:1.0:*:*:*:*:*:*:*

                      cpe:2.3:a:redhat:jboss_core_services:1.0:*:*:*:*:*:*:*

                      cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*

                      cpe:2.3:a:redhat:jboss_enterprise_application_platform:7.2.0:*:*:*:*:*:*:*

                      cpe:2.3:a:redhat:quay:3.0.0:*:*:*:*:*:*:*

                      cpe:2.3:a:redhat:openshift_service_mesh:1.0:*:*:*:*:*:*:*

                      cpe:2.3:a:redhat:jboss_enterprise_application_platform:7.3.0:*:*:*:*:*:*:*

                      Configuration 11

                      cpe:2.3:a:oracle:graalvm:19.2.0:*:*:*:enterprise:*:*:*

                      Configuration 12

                      cpe:2.3:a:mcafee:web_gateway:*:*:*:*:*:*:*:*
                      Start including
                      7.7.2.0
                      End excliding
                      7.7.2.24

                      cpe:2.3:a:mcafee:web_gateway:*:*:*:*:*:*:*:*
                      Start including
                      7.8.2.0
                      End excliding
                      7.8.2.13

                      cpe:2.3:a:mcafee:web_gateway:*:*:*:*:*:*:*:*
                      Start including
                      8.1.0
                      End excliding
                      8.2.0

                      Configuration 13

                      cpe:2.3:a:f5:nginx:*:*:*:*:*:*:*:*
                      Start including
                      1.9.5
                      End excliding
                      1.16.1

                      cpe:2.3:a:f5:nginx:*:*:*:*:*:*:*:*
                      Start including
                      1.17.0
                      End including
                      1.17.2

                      Configuration 14

                      cpe:2.3:a:nodejs:node.js:*:*:*:*:-:*:*:*
                      Start including
                      12.0.0
                      End excliding
                      12.8.1

                      cpe:2.3:a:nodejs:node.js:*:*:*:*:lts:*:*:*
                      Start including
                      8.0.0
                      End excliding
                      8.16.1

                      cpe:2.3:a:nodejs:node.js:*:*:*:*:lts:*:*:*
                      Start including
                      10.0.0
                      End excliding
                      10.16.3