Resource exhaustion in nghttp2 - CVE-2016-1544

 

Resource exhaustion in nghttp2 - CVE-2016-1544

Published: February 6, 2020 / Updated: July 17, 2020


Vulnerability identifier: #VU30377
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2016-1544
CWE-ID: CWE-400
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local authenticated user to perform service disruption.

nghttp2 before 1.7.1 allows remote attackers to cause a denial of service (memory exhaustion).


Affected software

nghttp2
Gentoo Linux
Fedora
SUSE OpenStack Cloud
SUSE OpenStack Cloud Crowbar
HPE Helion Openstack
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Server
nghttp2
libnghttp2-14
libnghttp2-14-32bit
libnghttp2-14-debuginfo
libnghttp2-14-debuginfo-32bit
nghttp2-debuginfo
nghttp2-debugsource
Dell EMC Storage Monitoring and Reporting (SMR)

How to mitigate CVE-2016-1544

Install update from vendor's website.

nghttp2 - update to 1.7.1
nghttp2 - addressed in versions 1.7.1-1.el7, 1.7.1-1.fc22, 1.7.1-1.fc23
libnghttp2-14 - update to 1.39.2-3.5.1
libnghttp2-14-32bit - update to 1.39.2-3.5.1
libnghttp2-14-debuginfo - update to 1.39.2-3.5.1
libnghttp2-14-debuginfo-32bit - update to 1.39.2-3.5.1
nghttp2-debuginfo - update to 1.39.2-3.5.1
nghttp2-debugsource - update to 1.39.2-3.5.1
Dell EMC Storage Monitoring and Reporting (SMR) - update to 4.6.0.0

External References

Related Security Bulletins