Resource exhaustion in Microsoft Windows and Windows Server - CVE-2019-9518
Published: August 13, 2019
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to improper validation of user-supplied input within the HTTP.sys driver when processing HTTP/2 requests. A remote attacker can send specially crafted HTTP packets to the affected system trigger resource exhaustion and perform a denial of service (DoS) attack.
Affected software
Windows Server
Red Hat Enterprise Linux for x86_64
Opensuse
Fedora
IBM Observability with Instana
IBM PureData System for Operational Analytics
Log Analysis
IBM Cloud Transformation Advisor
IBM Process Mining
IBM Spectrum Protect Storage Agent
Red Hat Software Collections
Fuse
AMQ Broker
Red Hat Process Automation Manager (formerly JBoss BPM Suite)
Contrail Networking
IBM Tivoli Application Dependency Discovery Manager
trafficserver (Debian package)
nodejs (Alpine package)
nodejs
watsonx.data
IBM Sterling Order Management
How to mitigate CVE-2019-9518
Fuse - addressed in versions 6.3.14, 7.5.0, 7.6.0
AMQ Broker - addressed in versions 7.4.3, 7.6
Red Hat Process Automation Manager (formerly JBoss BPM Suite) - update to 7.8.0
IBM Tivoli Application Dependency Discovery Manager - update to 7.3.0.7
trafficserver (Debian package) - update to 8.0.2+ds-1+deb10u1
nodejs (Alpine package) - update to 10.16.3-r0
IBM Process Mining - update to 1.12.0.4
watsonx.data - update to 2.0.2
IBM Spectrum Protect Storage Agent - update to 8.1.19
IBM Sterling Order Management - update to 10.0.2206.2
nodejs - addressed in versions 10.16.3-1.fc29, 10.16.3-1.fc30, 10-2920190816104510.6c81f848, 10-3020190816104510.a5b0195c
Contrail Networking - update to 2011.L5
External References
Related Security Bulletins
- Remote denial of service in HTTP/2 implementation in Microsoft Windows
- Debian update for trafficserver
- OpenSUSE Linux update for nodejs10
- OpenSUSE Linux update for nodejs8
- Red Hat update for nodejs:10
- Red Hat update for rh-nodejs10-nodejs
- Red Hat update for rh-nodejs8-nodejs
- Multiple vulnerabilities in Red Hat Fuse
- Multiple vulnerabilities in Red Hat JBoss Fuse/A-MQ
- Multiple vulnerabilities in Red Hat Fuse
- Multiple vulnerabilities in Red Hat AMQ Broker
- Multiple vulnerabilities in Red Hat Process Automation Manager
- Resource exhaustion in nodejs (Alpine package)
- Multiple vulnerabilities in IBM PureData System for Operational Analytics
- Multiple vulnerabilities in Juniper Networks Contrail Networking
- Multiple vulnerabilities in IBM Process Mining
- Multiple vulnerabilities in IBM Cloud Transformation Advisor
- Multiple vulnerabilities in IBM Cloud Transformation Advisor
- Multiple vulnerabilities in IBM Storage Protect Server
- Multiple vulnerabilities in IBM Observability with Instana (OnPrem)
- Multiple vulnerabilities in IBM Sterling Order Management
- Multiple vulnerabilities in IBM Operations Analytics - Log Analysis
- Multiple vulnerabilities in IBM watsonx.data
- Multiple vulnerabilities in AMQ Broker 7.4
- Fedora 30 Modular update for nodejs
- Fedora 29 update for nodejs
- Fedora 29 Modular update for nodejs
- Fedora 30 update for nodejs
- Multiple vulnerabilities in IBM Tivoli Application Dependency Discovery Manager