Resource management error - CVE-2019-9517

 

Resource management error - CVE-2019-9517

Published: August 20, 2019


Vulnerability identifier: #VU20340
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-9517
CWE-ID: CWE-399
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to incorrect implementation of HTTP/2 protocol. A remote attacker can  open the HTTP/2 window so the peer can send without constraint; however, they leave the TCP window closed so the peer cannot actually write (many of) the bytes on the wire. The attacker then sends a stream of requests for a large response object. Depending on how the servers queue the responses, this can consume excess memory, CPU, or both.

Affected software

Gentoo Linux
Amazon Linux AMI
Red Hat Enterprise Linux for x86_64
Slackware Linux
Opensuse
openEuler
Fedora
JBoss Core Services
AMQ Broker
Fuse
Red Hat Software Collections
IBM Cloud Transformation Advisor
Dell Secure Connect Gateway
IBM Process Mining
IBM Spectrum Protect Storage Agent
apache2 (Ubuntu package)
apache2 (Alpine package)
apache2 (Debian package)
nodejs (Alpine package)
mod_http2
mod_ssl
mod_session
mod_proxy_html
mod_md
mod_ldap
httpd-tools
httpd-help
httpd-filesystem
httpd-devel
httpd-debugsource
httpd
httpd-debuginfo
nodejs
Apache HTTP Server
IBM Tivoli Application Dependency Discovery Manager
Oracle Enterprise Manager Ops Center
Maximo Application Suite - IoT Component

How to mitigate CVE-2019-9517

Install updates from vendor's website.

apache2 (Ubuntu package) - addressed in versions 2.4.18-2ubuntu3.12, 2.4.18-2ubuntu3.13, 2.4.29-1ubuntu4.10, 2.4.29-1ubuntu4.11, 2.4.38-2ubuntu2.2, 2.4.38-2ubuntu2.3
Apache HTTP Server - update to 2.4.41
apache2 (Alpine package) - update to 2.4.41-r0
apache2 (Debian package) - update to 2.4.25-3+deb9u8
Dell Secure Connect Gateway - update to 5.12.00.10
AMQ Broker - addressed in versions 7.4.3, 7.6
Fuse - update to 7.6.0
IBM Tivoli Application Dependency Discovery Manager - update to 7.3.0.7
nodejs (Alpine package) - update to 10.16.3-r0
IBM Process Mining - update to 1.12.0.4
mod_http2 - addressed in versions 1.15.3-2.fc29, 1.15.3-2.fc30
mod_ssl - update to 2.4.34-18
mod_session - update to 2.4.34-18
mod_proxy_html - update to 2.4.34-18
mod_md - update to 2.4.34-18
mod_ldap - update to 2.4.34-18
httpd-tools - update to 2.4.34-18
httpd-help - update to 2.4.34-18
httpd-filesystem - update to 2.4.34-18
httpd-devel - update to 2.4.34-18
httpd-debugsource - update to 2.4.34-18
httpd - update to 2.4.34-18
httpd-debuginfo - update to 2.4.34-18
IBM Spectrum Protect Storage Agent - update to 8.1.19
Maximo Application Suite - IoT Component - addressed in versions 8.7.20, 8.8.16, 9.0.6
nodejs - addressed in versions 10.16.3-1.fc29, 10.16.3-1.fc30, 10-2920190816104510.6c81f848, 10-3020190816104510.a5b0195c

External References

Related Security Bulletins