PT-2018-2562 · Nginx+4 · Nginx+4

Gal Goldshtein

·

Publicado

2018-11-06

·

Atualizado

2024-10-04

·

CVE-2018-16844

CVSS v2.0

7.8

Alta

VetorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions nginx versions 1.14.0 through 1.14.1 nginx versions 1.15.0 through 1.15.6
Description The issue is related to the implementation of HTTP/2 in nginx, which can lead to excessive CPU usage. This problem affects nginx compiled with the ngx http v2 module, but only if the 'http2' option of the 'listen' directive is used in a configuration file. The vulnerability can be exploited by a remote attacker to cause a denial of service.
Recommendations For versions 1.14.0 through 1.14.1, update to version 1.14.1 or later. For versions 1.15.0 through 1.15.6, update to version 1.15.6 or later. As a temporary workaround, consider disabling the ngx http v2 module module or removing the 'http2' option from the 'listen' directive in the configuration file until a patch is available.

Correção

Resource Exhaustion

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2018-2601
BDU:2019-00983
CVE-2018-16844
DSA-4335-1
MGASA-2018-0459
OPENSUSE-SU-2019:0195-1
OPENSUSE-SU-2019:2120-1
OPENSUSE-SU-2019_0195-1
OPENSUSE-SU-2019_2120-1
RHSA-2018:3680
RHSA-2018:3681
SUSE-SU-2019:0334-1
SUSE-SU-2019:2309-1
USN-3812-1

Produtos afetados

Alt Linux
Apple Macos
Nginx
Suse
Ubuntu