Resource exhaustion in Microsoft Windows and Windows Server - CVE-2019-9518

 

Resource exhaustion in Microsoft Windows and Windows Server - CVE-2019-9518

Published: August 13, 2019


Vulnerability identifier: #VU20199
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-9518
CWE-ID: CWE-400
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to improper validation of user-supplied input within the HTTP.sys driver when processing HTTP/2 requests. A remote attacker can send specially crafted HTTP packets to the affected system trigger resource exhaustion and perform a denial of service (DoS) attack.



Affected software

Microsoft Windows
Windows Server
Red Hat Enterprise Linux for x86_64
Opensuse
Fedora
IBM Observability with Instana
IBM PureData System for Operational Analytics
Log Analysis
IBM Cloud Transformation Advisor
IBM Process Mining
IBM Spectrum Protect Storage Agent
Red Hat Software Collections
Fuse
AMQ Broker
Red Hat Process Automation Manager (formerly JBoss BPM Suite)
Contrail Networking
IBM Tivoli Application Dependency Discovery Manager
trafficserver (Debian package)
nodejs (Alpine package)
nodejs
watsonx.data
IBM Sterling Order Management

How to mitigate CVE-2019-9518

Install updates from vendor's website.

Log Analysis - update to 1.3.8
Fuse - addressed in versions 6.3.14, 7.5.0, 7.6.0
AMQ Broker - addressed in versions 7.4.3, 7.6
Red Hat Process Automation Manager (formerly JBoss BPM Suite) - update to 7.8.0
IBM Tivoli Application Dependency Discovery Manager - update to 7.3.0.7
trafficserver (Debian package) - update to 8.0.2+ds-1+deb10u1
nodejs (Alpine package) - update to 10.16.3-r0
IBM Process Mining - update to 1.12.0.4
watsonx.data - update to 2.0.2
IBM Spectrum Protect Storage Agent - update to 8.1.19
IBM Sterling Order Management - update to 10.0.2206.2
nodejs - addressed in versions 10.16.3-1.fc29, 10.16.3-1.fc30, 10-2920190816104510.6c81f848, 10-3020190816104510.a5b0195c
Contrail Networking - update to 2011.L5

External References

Related Security Bulletins