-
Notifications
You must be signed in to change notification settings - Fork 85
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
HTTP/2 implementations do not robustly handle abnormal traffic and resource exhaustion #1958
Comments
Dropping Caddy - unbuildable. |
Twisted update still not released. |
httpd 2.4.41 also fixed CVE-2019-10092, CVE-2019-10097, CVE-2019-10098. |
Twisted hasn't been actively developed on... |
Use AOSA-2019-0197 for Apache HTTP Server, AOSA-2019-0198 for nginx, AOSA-2019-0199 for go, AOSA-2019-0200 for nghttp2, AOSA-2019-0201 for Node.js. |
Ubuntu marks these Twisted CVEs as deferred: https://people.canonical.com/~ubuntu-security/cve/pkg/twisted.html |
AOSAs already assigned by @KexyBiscuit. |
Packages affected & Source progress:
Twisted <= v19.7.0See twisted: security update to 19.7.0 #1993Caddy < v1.0.2CVE IDs: CVE-2019-9511, CVE-2019-9512, CVE-2019-9513, CVE-2019-9514, CVE-2019-9515, CVE-2019-9516, CVE-2019-9517, CVE-2019-9518
Other security advisory IDs: VU#605641, USN-4099-1, DSA-4505-1, ASA-201908-13, ASA-201908-17, DSA-4511-1
Descriptions: Multiple HTTP/2 implementations are vulnerable to a variety of denial-of-service (DoS) attacks.
Patches: N/A
PoC(s): N/A
Architectural progress:
httpd
Apache HTTP Serveramd64
arm64
armel
ppc64
powerpc
nginx
amd64
arm64
armel
ppc64
powerpc
go
amd64
arm64
armel
nghttp2
amd64
arm64
armel
ppc64
powerpc
nodejs
Node.jsamd64
arm64
armel
- See twisted: security update to 19.7.0 #1993.twisted
Twistedcaddy
CaddyAMD64amd64
FTBFSThe text was updated successfully, but these errors were encountered: