Resource exhaustion in NGINX Open Source - CVE-2019-9511

 

Resource exhaustion in NGINX Open Source - CVE-2019-9511

Published: August 13, 2019 / Updated: August 13, 2019


Vulnerability identifier: #VU20196
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-9511
CWE-ID: CWE-400
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to improper input validation when processing HTTP/2 requests. A remote attacker can send a specially crafted HTTP/2 request the affected server, consume all available CPU resources and perform a denial of service (DoS) attack.

Successful exploitation of the vulnerability requires that support for HTTP/2 is enabled.


Affected software

NGINX Open Source
Arch Linux
Amazon Linux AMI
SUSE OpenStack Cloud
Fedora
Red Hat Enterprise Linux for x86_64
SUSE OpenStack Cloud Crowbar
HPE Helion Openstack
Microsoft Windows
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Server
Opensuse
Ubuntu
Windows Server
JBoss Core Services
AMQ Broker
JBoss Enterprise Application Platform
Red Hat Software Collections
nginx (Alpine package)
nginx (Ubuntu package)
nginx (Debian package)
nghttp2 (Debian package)
nghttp2 (Alpine package)
nodejs (Debian package)
nodejs (Alpine package)
nghttp2-server (Ubuntu package)
nghttp2-proxy (Ubuntu package)
nghttp2-client (Ubuntu package)
nghttp2 (Ubuntu package)
libnghttp2-14 (Ubuntu package)
nginx
mod_http2
nghttp2
libnghttp2-14-debuginfo
nghttp2-debugsource
nghttp2-debuginfo
libnghttp2-14-debuginfo-32bit
libnghttp2-14-32bit
libnghttp2-14
nodejs
IBM Cloud Transformation Advisor
IBM Process Mining
IBM Spectrum Protect Storage Agent
Quay
Oracle GraalVM Enterprise Edition
HPE Moonshot 1500 Chassis Manager

How to mitigate CVE-2019-9511

Install updates from vendor's website.

NGINX Open Source - addressed in versions 1.16.1, 1.17.3
nginx (Alpine package) - addressed in versions 1.14.2-r1, 1.14.2-r2
nginx (Ubuntu package) - addressed in versions 1.10.3-0ubuntu0.16.04.4, 1.14.0-0ubuntu1.4, 1.15.9-0ubuntu1.1
nginx (Debian package) - update to 1.10.3-1+deb9u3
nghttp2 (Debian package) - addressed in versions 1.18.1-1+deb9u1, 1.36.0-2+deb10u1
nghttp2 (Alpine package) - addressed in versions 1.35.1-r1, 1.39.2-r0
Quay - update to 3.1.1
AMQ Broker - addressed in versions 7.4.3, 7.6
JBoss Enterprise Application Platform - update to 7.2.5
nodejs (Debian package) - update to 10.19.0~dfsg1-1
nodejs (Alpine package) - update to 10.16.3-r0
nghttp2-server (Ubuntu package) - addressed in versions Ubuntu Pro, 1.40.0-1ubuntu0.3, 1.43.0-1ubuntu0.2, 1.55.1-1ubuntu0.2, 1.59.0-1ubuntu0.1
nghttp2-proxy (Ubuntu package) - addressed in versions Ubuntu Pro, 1.40.0-1ubuntu0.3, 1.43.0-1ubuntu0.2, 1.55.1-1ubuntu0.2, 1.59.0-1ubuntu0.1
nghttp2-client (Ubuntu package) - addressed in versions Ubuntu Pro, 1.40.0-1ubuntu0.3, 1.43.0-1ubuntu0.2, 1.55.1-1ubuntu0.2, 1.59.0-1ubuntu0.1
nghttp2 (Ubuntu package) - addressed in versions Ubuntu Pro, 1.40.0-1ubuntu0.3, 1.43.0-1ubuntu0.2, 1.55.1-1ubuntu0.2, 1.59.0-1ubuntu0.1
libnghttp2-14 (Ubuntu package) - addressed in versions Ubuntu Pro, 1.40.0-1ubuntu0.3, 1.43.0-1ubuntu0.2, 1.55.1-1ubuntu0.2, 1.59.0-1ubuntu0.1
nginx - addressed in versions mainline-2920190816153353.6c81f848, mainline-3020190816153353.a5b0195c, 1.16.1-1.fc29, 1.16.1-1.fc30
IBM Process Mining - update to 1.12.0.4
mod_http2 - addressed in versions 1.15.3-2.fc29, 1.15.3-2.fc30
nghttp2 - addressed in versions 1.31.1-2.el7, 1.39.2-1.fc29, 1.39.2-1.fc30
libnghttp2-14-debuginfo - update to 1.39.2-3.5.1
nghttp2-debugsource - update to 1.39.2-3.5.1
nghttp2-debuginfo - update to 1.39.2-3.5.1
libnghttp2-14-debuginfo-32bit - update to 1.39.2-3.5.1
libnghttp2-14-32bit - update to 1.39.2-3.5.1
libnghttp2-14 - update to 1.39.2-3.5.1
HPE Moonshot 1500 Chassis Manager - update to 4.0-b43
IBM Spectrum Protect Storage Agent - update to 8.1.19
nodejs - addressed in versions 12-2920190821145457.6c81f848, 12-3020190821145457.a5b0195c

External References

Related Security Bulletins