CVE-2019-9512
HIGH7.5EPSS 50.8%golang.org/x/net/http vulnerable to a reset flood
發布日:2022/5/24修改日:2026/2/4
也稱為:GHSA-39qc-96h7-956fGHSA-hgr8-6h9x-f7q9ALPINE-CVE-2019-9512CGA-hxrg-2m2v-635rDEBIAN-CVE-2019-9512GO-2022-0536
描述
Some HTTP/2 implementations are vulnerable to a reset flood, potentially leading to a denial of service. Servers that accept direct connections from untrusted clients could be remotely made to allocate an unlimited amount of memory, until the program crashes. The attacker opens a number of streams and sends an invalid request over each stream that should solicit a stream of RST_STREAM frames from the peer. Depending on how the peer queues the RST_STREAM frames, this can consume excess memory, CPU, or both. ### Specific Go Packages Affected golang.org/x/net/http2
受影響套件(9)
- Alpine/nodejsfrom 0, < 10.16.3-r0
- Debian/golang-golang-x-net-devfrom 0, < 1:0.0+git20161013.8b4af36+dfsg-3+deb9u1
- Debian/h2ofrom 0, < 2.2.5+dfsg2-3
- Debian/h2ofrom 0, < 2.2.5+dfsg2-2+deb10u1
- Debian/trafficserverfrom 0, < 8.0.5+ds-1
- Go/golang.org/x/netfrom 0, < 0.0.0-20190813141303-74dc4d7220e7
- Go/golang.org/x/netfrom 0, < 0.0.0-20190813141303-74dc4d7220e7
- Go/golang.org/x/netfrom 0, < 0.0.0-20190813141303-74dc4d7220e7
- Go/stdlibfrom 0, < 1.11.13, >= 1.12.0-0, < 1.12.8
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH7.5 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
參考連結(78)
- ADVISORYhttps://nvd.nist.gov/vuln/detail/CVE-2019-9512
- ADVISORYhttps://nvd.nist.gov/vuln/detail/CVE-2019-9514
- ADVISORYhttps://security.alpinelinux.org/vuln/CVE-2019-9512
- ADVISORYhttps://security-tracker.debian.org/tracker/CVE-2019-9512
- WEBhttp://lists.opensuse.org/opensuse-security-announce/2019-08/msg00076.html
- WEBhttp://lists.opensuse.org/opensuse-security-announce/2019-09/msg00002.html
- WEBhttp://lists.opensuse.org/opensuse-security-announce/2019-09/msg00011.html
- WEBhttp://lists.opensuse.org/opensuse-security-announce/2019-09/msg00021.html
- WEBhttp://lists.opensuse.org/opensuse-security-announce/2019-09/msg00031.html
- WEBhttp://lists.opensuse.org/opensuse-security-announce/2019-09/msg00032.html
- WEBhttp://lists.opensuse.org/opensuse-security-announce/2019-09/msg00038.html
- WEBhttps://access.redhat.com/errata/RHSA-2019:2594
- WEBhttps://access.redhat.com/errata/RHSA-2019:2661
- WEBhttps://access.redhat.com/errata/RHSA-2019:2682
- WEBhttps://access.redhat.com/errata/RHSA-2019:2690
- WEBhttps://access.redhat.com/errata/RHSA-2019:2726
- WEBhttps://access.redhat.com/errata/RHSA-2019:2766
- WEBhttps://access.redhat.com/errata/RHSA-2019:2769
- WEBhttps://access.redhat.com/errata/RHSA-2019:2796
- WEBhttps://access.redhat.com/errata/RHSA-2019:2861
- WEBhttps://access.redhat.com/errata/RHSA-2019:2925
- WEBhttps://access.redhat.com/errata/RHSA-2019:2939
- WEBhttps://access.redhat.com/errata/RHSA-2019:2955
- WEBhttps://access.redhat.com/errata/RHSA-2019:2966
- WEBhttps://access.redhat.com/errata/RHSA-2019:3131
- WEBhttps://access.redhat.com/errata/RHSA-2019:3245
- WEBhttps://access.redhat.com/errata/RHSA-2019:3265
- WEBhttps://access.redhat.com/errata/RHSA-2019:3892
- WEBhttps://access.redhat.com/errata/RHSA-2019:3906
- WEBhttps://access.redhat.com/errata/RHSA-2019:4018
- WEBhttps://access.redhat.com/errata/RHSA-2019:4019
- WEBhttps://access.redhat.com/errata/RHSA-2019:4020
- WEBhttps://access.redhat.com/errata/RHSA-2019:4021
- WEBhttps://access.redhat.com/errata/RHSA-2019:4040
- WEBhttps://access.redhat.com/errata/RHSA-2019:4041
- WEBhttps://access.redhat.com/errata/RHSA-2019:4042
- WEBhttps://access.redhat.com/errata/RHSA-2019:4045
- WEBhttps://access.redhat.com/errata/RHSA-2019:4269
- WEBhttps://access.redhat.com/errata/RHSA-2019:4273
- WEBhttps://access.redhat.com/errata/RHSA-2019:4352
- WEBhttps://access.redhat.com/errata/RHSA-2020:0406
- WEBhttps://access.redhat.com/errata/RHSA-2020:0727
- WEBhttp://seclists.org/fulldisclosure/2019/Aug/16
- WEBhttps://github.com/Netflix/security-bulletins/blob/master/advisories/third-party/2019-002.md
- WEBhttps://go.dev/cl/190137
- WEBhttps://go.dev/issue/33606
- WEBhttps://go.googlesource.com/go/+/145e193131eb486077b66009beb051aba07c52a5
- WEBhttps://groups.google.com/g/golang-announce/c/65QixT3tcmg/m/DrFiG6vvCwAJ
- WEBhttps://kb.cert.org/vuls/id/605641
- WEBhttps://kc.mcafee.com/corporate/index?page=content&id=SB10296
- … 另有 28 筆