Lucene search

K
freebsdFreeBSD4DA51989-5A8B-4EB9-B442-46D94EC0802D
HistoryApr 27, 2023 - 12:00 a.m.

h2o -- Malformed HTTP/1.1 causes Out-of-Memory Denial of Service

2023-04-2700:00:00
vuxml.freebsd.org
5
http malformation
worker process crash
out-of-memory
dos
unix

8.2 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H

0.002 Low

EPSS

Percentile

58.8%

Elijah Glover reports:

   Malformed HTTP/1.1 requests can crash worker processes.
   occasionally locking up child workers and causing denial of
   service, and an outage dropping any open connections.
OSVersionArchitecturePackageVersionFilename
FreeBSDanynoarchh2o<= 2.2.6UNKNOWN
FreeBSDanynoarchh2o-devel< 2.3.0.d.20230427UNKNOWN

8.2 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H

0.002 Low

EPSS

Percentile

58.8%

Related for 4DA51989-5A8B-4EB9-B442-46D94EC0802D