Resource management error - CVE-2019-9517
Published: August 20, 2019
Vulnerability identifier: #VU20340
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-9517
CWE-ID: CWE-399
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to incorrect implementation of HTTP/2 protocol. A remote attacker can open the HTTP/2 window so the peer can send without constraint; however, they leave the TCP window closed so the peer cannot actually write (many of) the bytes on the wire. The attacker then sends a stream of requests for a large response object. Depending on how the servers queue the responses, this can consume excess memory, CPU, or both.Affected software
Gentoo Linux
Amazon Linux AMI
Red Hat Enterprise Linux for x86_64
Slackware Linux
Opensuse
openEuler
Fedora
JBoss Core Services
AMQ Broker
Fuse
Red Hat Software Collections
IBM Cloud Transformation Advisor
Dell Secure Connect Gateway
IBM Process Mining
IBM Spectrum Protect Storage Agent
apache2 (Ubuntu package)
apache2 (Alpine package)
apache2 (Debian package)
nodejs (Alpine package)
mod_http2
mod_ssl
mod_session
mod_proxy_html
mod_md
mod_ldap
httpd-tools
httpd-help
httpd-filesystem
httpd-devel
httpd-debugsource
httpd
httpd-debuginfo
nodejs
Apache HTTP Server
IBM Tivoli Application Dependency Discovery Manager
Oracle Enterprise Manager Ops Center
Maximo Application Suite - IoT Component
Amazon Linux AMI
Red Hat Enterprise Linux for x86_64
Slackware Linux
Opensuse
openEuler
Fedora
JBoss Core Services
AMQ Broker
Fuse
Red Hat Software Collections
IBM Cloud Transformation Advisor
Dell Secure Connect Gateway
IBM Process Mining
IBM Spectrum Protect Storage Agent
apache2 (Ubuntu package)
apache2 (Alpine package)
apache2 (Debian package)
nodejs (Alpine package)
mod_http2
mod_ssl
mod_session
mod_proxy_html
mod_md
mod_ldap
httpd-tools
httpd-help
httpd-filesystem
httpd-devel
httpd-debugsource
httpd
httpd-debuginfo
nodejs
Apache HTTP Server
IBM Tivoli Application Dependency Discovery Manager
Oracle Enterprise Manager Ops Center
Maximo Application Suite - IoT Component
How to mitigate CVE-2019-9517
Install updates from vendor's website.
apache2 (Ubuntu package) - addressed in versions 2.4.18-2ubuntu3.12, 2.4.18-2ubuntu3.13, 2.4.29-1ubuntu4.10, 2.4.29-1ubuntu4.11, 2.4.38-2ubuntu2.2, 2.4.38-2ubuntu2.3
Apache HTTP Server - update to 2.4.41
apache2 (Alpine package) - update to 2.4.41-r0
apache2 (Debian package) - update to 2.4.25-3+deb9u8
Dell Secure Connect Gateway - update to 5.12.00.10
AMQ Broker - addressed in versions 7.4.3, 7.6
Fuse - update to 7.6.0
IBM Tivoli Application Dependency Discovery Manager - update to 7.3.0.7
nodejs (Alpine package) - update to 10.16.3-r0
IBM Process Mining - update to 1.12.0.4
mod_http2 - addressed in versions 1.15.3-2.fc29, 1.15.3-2.fc30
mod_ssl - update to 2.4.34-18
mod_session - update to 2.4.34-18
mod_proxy_html - update to 2.4.34-18
mod_md - update to 2.4.34-18
mod_ldap - update to 2.4.34-18
httpd-tools - update to 2.4.34-18
httpd-help - update to 2.4.34-18
httpd-filesystem - update to 2.4.34-18
httpd-devel - update to 2.4.34-18
httpd-debugsource - update to 2.4.34-18
httpd - update to 2.4.34-18
httpd-debuginfo - update to 2.4.34-18
IBM Spectrum Protect Storage Agent - update to 8.1.19
Maximo Application Suite - IoT Component - addressed in versions 8.7.20, 8.8.16, 9.0.6
nodejs - addressed in versions 10.16.3-1.fc29, 10.16.3-1.fc30, 10-2920190816104510.6c81f848, 10-3020190816104510.a5b0195c
Apache HTTP Server - update to 2.4.41
apache2 (Alpine package) - update to 2.4.41-r0
apache2 (Debian package) - update to 2.4.25-3+deb9u8
Dell Secure Connect Gateway - update to 5.12.00.10
AMQ Broker - addressed in versions 7.4.3, 7.6
Fuse - update to 7.6.0
IBM Tivoli Application Dependency Discovery Manager - update to 7.3.0.7
nodejs (Alpine package) - update to 10.16.3-r0
IBM Process Mining - update to 1.12.0.4
mod_http2 - addressed in versions 1.15.3-2.fc29, 1.15.3-2.fc30
mod_ssl - update to 2.4.34-18
mod_session - update to 2.4.34-18
mod_proxy_html - update to 2.4.34-18
mod_md - update to 2.4.34-18
mod_ldap - update to 2.4.34-18
httpd-tools - update to 2.4.34-18
httpd-help - update to 2.4.34-18
httpd-filesystem - update to 2.4.34-18
httpd-devel - update to 2.4.34-18
httpd-debugsource - update to 2.4.34-18
httpd - update to 2.4.34-18
httpd-debuginfo - update to 2.4.34-18
IBM Spectrum Protect Storage Agent - update to 8.1.19
Maximo Application Suite - IoT Component - addressed in versions 8.7.20, 8.8.16, 9.0.6
nodejs - addressed in versions 10.16.3-1.fc29, 10.16.3-1.fc30, 10-2920190816104510.6c81f848, 10-3020190816104510.a5b0195c
External References
- http://www.openwall.com/lists/oss-security/2019/08/15/7
- https://github.com/Netflix/security-bulletins/blob/master/advisories/third-party/2019-002.md
- https://kb.cert.org/vuls/id/605641/
- https://lists.apache.org/thread.html/4610762456644181b267c846423b3a990bd4aaea1886ecc7d51febdb@%3Cannounce.httpd.apache.org%3E
- https://lists.apache.org/thread.html/56c2e7cc9deb1c12a843d0dc251ea7fd3e7e80293cde02fcd65286ba@%3Ccvs.httpd.apache.org%3E
- https://lists.apache.org/thread.html/d89f999e26dfb1d50f247ead1fe8538014eb412b2dbe5be4b1a9ef50@%3Cdev.httpd.apache.org%3E
- https://lists.apache.org/thread.html/ec97fdfc1a859266e56fef084353a34e0a0b08901b3c1aa317a43c8c@%3Cdev.httpd.apache.org%3E
- https://support.f5.com/csp/article/K02591030
- https://www.synology.com/security/advisory/Synology_SA_19_33
Related Security Bulletins
- Multiple vulnerabilities in Apache HTTP Server
- Debian update for apache2
- Ubuntu update for Apache HTTP Server
- OpenSUSE Linux update for apache2
- Gentoo update for Apache
- OpenSUSE Linux update for nodejs10
- OpenSUSE Linux update for nodejs8
- Ubuntu regression update for Apache HTTP Server
- Red Hat update for httpd:2.4
- Red Hat update for nodejs:10
- Red Hat update for rh-nodejs10-nodejs
- Red Hat update for Red Hat JBoss Core Services Apache HTTP Server 2.4.29 SP3
- Red Hat update for httpd24-httpd and httpd24-nghttp2
- Red Hat update for Red Hat JBoss Core Services Apache HTTP Server 2.4.29 SP3
- Red Hat update for rh-nodejs8-nodejs
- Amazon Linux AMI update for httpd24
- Red Hat JBoss Core Services update for Apache HTTP Server 2.4.37
- Red Hat JBoss Core Services update for Apache HTTP Server 2.4.37 (RHEL 6)
- Red Hat JBoss Core Services update Apache HTTP Server 2.4.37 (RHEL 7)
- Multiple vulnerabilities in Red Hat Fuse
- Multiple vulnerabilities in Red Hat AMQ Broker
- Slackware Linux update for httpd
- Multiple vulnerabilities in Oracle Enterprise Manager Ops Center
- Resource management error in apache2 (Alpine package)
- Resource management error in nodejs (Alpine package)
- Multiple vulnerabilities in DELL Secure Connect Gateway Security
- Multiple vulnerabilities in IBM Process Mining
- Multiple vulnerabilities in IBM Cloud Transformation Advisor
- Multiple vulnerabilities in IBM Cloud Transformation Advisor
- Multiple vulnerabilities in IBM Storage Protect Server
- openEuler 20.03 LTS update for httpd
- Multiple vulnerabilities in IBM Maximo Application Suite - IoT Component
- Multiple vulnerabilities in AMQ Broker 7.4
- Fedora 30 Modular update for nodejs
- Fedora 29 update for nodejs
- Fedora 29 Modular update for nodejs
- Fedora 30 update for nodejs
- Fedora 29 update for mod_http2
- Fedora 30 update for mod_http2
- Multiple vulnerabilities in IBM Tivoli Application Dependency Discovery Manager