CVE-2019-9513

Description

Some HTTP/2 implementations are vulnerable to resource loops, potentially leading to a denial of service. The attacker creates multiple request streams and continually shuffles the priority of the streams in a way that causes substantial churn to the priority tree. This can consume excess CPU.

Risk Information

Base Score
7.5
MODERATE
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:P/RL:O/RC:C
EPSS Score
Exploitation Probability
7.309

Associated Vulnerability

VulnerabilityOS Platform
Windows Information Disclosure Vulnerability for Windows 10 Version 1607 for x86-based Systems (KB4512517)Windows
Windows Information Disclosure Vulnerability for Windows 10 Version 1803 for x64-based Systems (KB4512501)Windows
Windows Information Disclosure Vulnerability for Windows Server 2016 (1803) for x64-based Systems (KB4512501)Windows
Windows Information Disclosure Vulnerability for Windows 10 Version 1803 for x86-based Systems (KB4512501)Windows
Windows Information Disclosure Vulnerability for Windows 10 Version 1709 for x64-based Systems (KB4512516)Windows
Windows Information Disclosure Vulnerability for Windows 10 Version 1709 for x86-based Systems (KB4512516)Windows
Windows Information Disclosure Vulnerability for Windows 10 Version 1903 for x64-based Systems (KB4512508)Windows
Windows Information Disclosure Vulnerability for Windows Server, version 1903 for x64-based Systems (KB4512508)Windows
Windows Information Disclosure Vulnerability for Windows 10 Version 1903 for x86-based Systems (KB4512508)Windows
Windows Information Disclosure Vulnerability for Windows 10 Version 1703 for x64-based Systems (KB4512507)Windows
Windows Information Disclosure Vulnerability for Windows 10 Version 1703 for x86-based Systems (KB4512507)Windows
Windows Information Disclosure Vulnerability for Windows 10 Version 1607 for x64-based Systems (KB4512517)Windows
Windows Information Disclosure Vulnerability for Windows Server 2016 for x64-based Systems (KB4512517)Windows
Windows Information Disclosure Vulnerability for Windows Server 2019 for x64-based Systems (KB4511553)Windows
Windows Information Disclosure Vulnerability for Windows 10 Version 1809 for x64-based Systems (KB4511553)Windows
Windows Information Disclosure Vulnerability for Windows 10 Version 1809 for x86-based Systems (KB4511553)Windows
Windows Information Disclosure Vulnerability for Windows 10 Version 1507 for x86-based Systems (KB4512497)Windows
Windows Information Disclosure Vulnerability for Windows 10 Version 1507 for x64-based Systems (KB4512497)Windows
Windows Information Disclosure Vulnerability for Windows 10 Version 1703 for x64-based Systems (KB4512507)Windows
Windows Information Disclosure Vulnerability for Windows 10 Version 1703 for x86-based Systems (KB4512507)Windows
Windows Information Disclosure Vulnerability for Windows 10 Version 1703 for x64-based Systems (KB4512507)Windows
Windows Information Disclosure Vulnerability for Windows 10 Version 1703 for x86-based Systems (KB4512507)Windows
Multiple vulnerabilities are fixed in Node.js 12 (12.22.12)Windows
Multiple vulnerabilities are fixed in Node.js 18 (x64) (18.16.1)Windows
Multiple vulnerabilities are fixed in Node.js 18 (18.16.1)Windows
Multiple vulnerabilities are fixed in Node.js (x64) (10.16.3)Windows
Multiple vulnerabilities are fixed in Node.js (10.16.3)Windows
Multiple vulnerabilities are fixed in Node.js 8 8.16.1Windows
Multiple vulnerabilities are fixed in Node.js 8 (x64) 8.16.1Windows
Multiple vulnerabilities are fixed in Node.js 12 12.8.1Windows
Vulnerabilities CVE-2019-9511,CVE-2019-9513,CVE-2019-9516 are fixed in Nginx 1.17.3Windows
Multiple Vulnerabilities are affected in IBM Sterling B2B Integrator 6.0.3.1Windows
Multiple Vulnerabilities are affected in IBM Sterling B2B Integrator 5.2.6.5Windows
Multiple Vulnerabilities are affected in IBM MQ 9.1Windows
Multiple Vulnerabilities are affected in IBM Tivoli Application Dependency Discovery Manager 7.3.0.7Windows
small, powerful, scalable web/proxy server (USN-4099-1) nginx-core_1.14.0-0ubuntu1.4_i386.debLinux
small, powerful, scalable web/proxy server (USN-4099-1) nginx-core_1.14.0-0ubuntu1.4_amd64.debLinux
small, powerful, scalable web/proxy server (USN-4099-1) nginx-core_1.15.9-0ubuntu1.1_i386.debLinux
small, powerful, scalable web/proxy server (USN-4099-1) nginx-core_1.15.9-0ubuntu1.1_amd64.debLinux
small, powerful, scalable web/proxy server (USN-4099-1) nginx-core_1.10.3-0ubuntu0.16.04.4_i386.debLinux
small, powerful, scalable web/proxy server (USN-4099-1) nginx-core_1.10.3-0ubuntu0.16.04.4_amd64.debLinux
small, powerful, scalable web/proxy server (USN-4099-1) nginx-full_1.14.0-0ubuntu1.4_i386.debLinux
small, powerful, scalable web/proxy server (USN-4099-1) nginx-full_1.14.0-0ubuntu1.4_amd64.debLinux
small, powerful, scalable web/proxy server (USN-4099-1) nginx-full_1.15.9-0ubuntu1.1_i386.debLinux
small, powerful, scalable web/proxy server (USN-4099-1) nginx-full_1.15.9-0ubuntu1.1_amd64.debLinux
small, powerful, scalable web/proxy server (USN-4099-1) nginx-full_1.10.3-0ubuntu0.16.04.4_i386.debLinux
small, powerful, scalable web/proxy server (USN-4099-1) nginx-full_1.10.3-0ubuntu0.16.04.4_amd64.debLinux
small, powerful, scalable web/proxy server (USN-4099-1) nginx-light_1.14.0-0ubuntu1.4_i386.debLinux
small, powerful, scalable web/proxy server (USN-4099-1) nginx-light_1.14.0-0ubuntu1.4_amd64.debLinux
small, powerful, scalable web/proxy server (USN-4099-1) nginx-light_1.15.9-0ubuntu1.1_i386.debLinux
small, powerful, scalable web/proxy server (USN-4099-1) nginx-light_1.15.9-0ubuntu1.1_amd64.debLinux
small, powerful, scalable web/proxy server (USN-4099-1) nginx-light_1.10.3-0ubuntu0.16.04.4_i386.debLinux
small, powerful, scalable web/proxy server (USN-4099-1) nginx-light_1.10.3-0ubuntu0.16.04.4_amd64.debLinux
small, powerful, scalable web/proxy server (USN-4099-1) nginx-common_1.14.0-0ubuntu1.4_all.debLinux
small, powerful, scalable web/proxy server (USN-4099-1) nginx-common_1.15.9-0ubuntu1.1_all.debLinux
small, powerful, scalable web/proxy server (USN-4099-1) nginx-common_1.10.3-0ubuntu0.16.04.4_all.debLinux
small, powerful, scalable web/proxy server (USN-4099-1) nginx-extras_1.14.0-0ubuntu1.4_i386.debLinux
small, powerful, scalable web/proxy server (USN-4099-1) nginx-extras_1.14.0-0ubuntu1.4_amd64.debLinux
small, powerful, scalable web/proxy server (USN-4099-1) nginx-extras_1.15.9-0ubuntu1.1_i386.debLinux
small, powerful, scalable web/proxy server (USN-4099-1) nginx-extras_1.15.9-0ubuntu1.1_amd64.debLinux
small, powerful, scalable web/proxy server (USN-4099-1) nginx-extras_1.10.3-0ubuntu0.16.04.4_i386.debLinux
small, powerful, scalable web/proxy server (USN-4099-1) nginx-extras_1.10.3-0ubuntu0.16.04.4_amd64.debLinux
nginx security update(DSA-4505-1) nginx_1.10.3-1+deb9u3_all.debLinux
nginx security update(DSA-4505-1) nginx_1.14.2-2+deb10u1_all.debLinux
nghttp2 security update(DSA-4511-1) nghttp2_1.18.1-1+deb9u1_all.debLinux
nghttp2 security update(DSA-4511-1) nghttp2_1.36.0-2+deb10u1_all.debLinux
(RHSA-2019:2692) nghttp2 security update libnghttp2-1.33.0-1.el8_0.1.i686.rpmLinux
(RHSA-2019:2692) nghttp2 security update libnghttp2-1.33.0-1.el8_0.1.x86_64.rpmLinux
(RHSA-2019:2692) nghttp2 security update nghttp2-debugsource-1.33.0-1.el8_0.1.i686.rpmLinux
(RHSA-2019:2692) nghttp2 security update nghttp2-debugsource-1.33.0-1.el8_0.1.x86_64.rpmLinux
(RHSA-2019:2799) nginx:1.14 security update nginx-1.14.1-9.module+el8.0.0+4108+af250afe.x86_64.rpmLinux
(RHSA-2019:2799) nginx:1.14 security update nginx-all-modules-1.14.1-9.module+el8.0.0+4108+af250afe.noarch.rpmLinux
(RHSA-2019:2799) nginx:1.14 security update nginx-debugsource-1.14.1-9.module+el8.0.0+4108+af250afe.x86_64.rpmLinux
(RHSA-2019:2799) nginx:1.14 security update nginx-filesystem-1.14.1-9.module+el8.0.0+4108+af250afe.noarch.rpmLinux
(RHSA-2019:2799) nginx:1.14 security update nginx-mod-http-image-filter-1.14.1-9.module+el8.0.0+4108+af250afe.x86_64.rpmLinux
(RHSA-2019:2799) nginx:1.14 security update nginx-mod-http-perl-1.14.1-9.module+el8.0.0+4108+af250afe.x86_64.rpmLinux
(RHSA-2019:2799) nginx:1.14 security update nginx-mod-http-xslt-filter-1.14.1-9.module+el8.0.0+4108+af250afe.x86_64.rpmLinux
(RHSA-2019:2799) nginx:1.14 security update nginx-mod-mail-1.14.1-9.module+el8.0.0+4108+af250afe.x86_64.rpmLinux
(RHSA-2019:2799) nginx:1.14 security update nginx-mod-stream-1.14.1-9.module+el8.0.0+4108+af250afe.x86_64.rpmLinux
nodejs security update(DSA-4669-1) nodejs_10.19.0~dfsg1-1_i386.debLinux
nodejs security update(DSA-4669-1) nodejs_10.19.0~dfsg1-1_amd64.debLinux
Nginx update (ELSA-2019-2799) nginx-1.14.1-9.0.1.module+el8.0.0+5347+9282027e.x86_64.rpmLinux
Nginx-mod-http-image-filter update (ELSA-2019-2799) nginx-mod-http-image-filter-1.14.1-9.0.1.module+el8.0.0+5347+9282027e.x86_64.rpmLinux
Nginx-mod-http-perl update (ELSA-2019-2799) nginx-mod-http-perl-1.14.1-9.0.1.module+el8.0.0+5347+9282027e.x86_64.rpmLinux
Nginx-mod-http-xslt-filter update (ELSA-2019-2799) nginx-mod-http-xslt-filter-1.14.1-9.0.1.module+el8.0.0+5347+9282027e.x86_64.rpmLinux
Nginx-mod-mail update (ELSA-2019-2799) nginx-mod-mail-1.14.1-9.0.1.module+el8.0.0+5347+9282027e.x86_64.rpmLinux
Nginx-mod-stream update (ELSA-2019-2799) nginx-mod-stream-1.14.1-9.0.1.module+el8.0.0+5347+9282027e.x86_64.rpmLinux
Nginx-all-modules update (ELSA-2019-2799) nginx-all-modules-1.14.1-9.0.1.module+el8.0.0+5347+9282027e.noarch.rpmLinux
Nginx-filesystem update (ELSA-2019-2799) nginx-filesystem-1.14.1-9.0.1.module+el8.0.0+5347+9282027e.noarch.rpmLinux
Libnghttp2 update (ELSA-2020-2755) libnghttp2-1.33.0-3.el8_2.1.x86_64.rpmLinux
Libnghttp2-devel update (ELSA-2020-2755) libnghttp2-devel-1.33.0-3.el8_2.1.x86_64.rpmLinux
Nghttp2 update (ELSA-2020-2755) nghttp2-1.33.0-3.el8_2.1.x86_64.rpmLinux
Libnghttp2 update (ELSA-2020-2755) libnghttp2-1.33.0-3.el8_2.1.i686.rpmLinux
Libnghttp2-devel update (ELSA-2020-2755) libnghttp2-devel-1.33.0-3.el8_2.1.i686.rpmLinux
SUSE-SU-2021:0932-1(SUSE Linux Enterprise Server 12-SP5 ) libnghttp2-14-1.39.2-3.5.1.x86_64.rpmLinux
SUSE-SU-2021:0932-1(SUSE Linux Enterprise Server 12-SP5 ) libnghttp2-14-32bit-1.39.2-3.5.1.x86_64.rpmLinux
SUSE-SU-2021:0932-1(SUSE Linux Enterprise Server 12-SP5 ) libnghttp2-14-debuginfo-1.39.2-3.5.1.x86_64.rpmLinux
SUSE-SU-2021:0932-1(SUSE Linux Enterprise Server 12-SP5 ) libnghttp2-14-debuginfo-32bit-1.39.2-3.5.1.x86_64.rpmLinux
SUSE-SU-2021:0932-1(SUSE Linux Enterprise Server 12-SP5 ) nghttp2-debuginfo-1.39.2-3.5.1.x86_64.rpmLinux
SUSE-SU-2021:0932-1(SUSE Linux Enterprise Server 12-SP5 ) nghttp2-debugsource-1.39.2-3.5.1.x86_64.rpmLinux
(CESA-2019:2692) nghttp2 security update libnghttp2-1.33.0-1.el8_0.1.i686.rpmLinux
(CESA-2019:2692) nghttp2 security update libnghttp2-1.33.0-1.el8_0.1.x86_64.rpmLinux
(RHSA-2019:2799)Important: security update nginx-debuginfo-1.14.1-9.module+el8.0.0+4108+af250afe.x86_64.rpmLinux
(RHSA-2019:2799)Important: security update nginx-mod-http-image-filter-debuginfo-1.14.1-9.module+el8.0.0+4108+af250afe.x86_64.rpmLinux
(RHSA-2019:2799)Important: security update nginx-mod-http-perl-debuginfo-1.14.1-9.module+el8.0.0+4108+af250afe.x86_64.rpmLinux
(RHSA-2019:2799)Important: security update nginx-mod-http-xslt-filter-debuginfo-1.14.1-9.module+el8.0.0+4108+af250afe.x86_64.rpmLinux
(RHSA-2019:2799)Important: security update nginx-mod-mail-debuginfo-1.14.1-9.module+el8.0.0+4108+af250afe.x86_64.rpmLinux
(RHSA-2019:2799)Important: security update nginx-mod-stream-debuginfo-1.14.1-9.module+el8.0.0+4108+af250afe.x86_64.rpmLinux
Important: nginx:1.14 security update nginx-1.14.1-9.module_el8.3.0+2165+af250afe.alma.x86_64.rpmLinux
Important: nginx:1.14 security update nginx-all-modules-1.14.1-9.module_el8.3.0+2165+af250afe.alma.noarch.rpmLinux
Important: nginx:1.14 security update nginx-filesystem-1.14.1-9.module_el8.3.0+2165+af250afe.alma.noarch.rpmLinux
Important: nginx:1.14 security update nginx-mod-http-image-filter-1.14.1-9.module_el8.3.0+2165+af250afe.alma.x86_64.rpmLinux
Important: nginx:1.14 security update nginx-mod-http-perl-1.14.1-9.module_el8.3.0+2165+af250afe.alma.x86_64.rpmLinux
Important: nginx:1.14 security update nginx-mod-http-xslt-filter-1.14.1-9.module_el8.3.0+2165+af250afe.alma.x86_64.rpmLinux
Important: nginx:1.14 security update nginx-mod-mail-1.14.1-9.module_el8.3.0+2165+af250afe.alma.x86_64.rpmLinux
Important: nginx:1.14 security update nginx-mod-stream-1.14.1-9.module_el8.3.0+2165+af250afe.alma.x86_64.rpmLinux
Uncontrolled Resource Consumption Vulnerability (CVE-2019-9513)NCM

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-272142019-08 Cumulative Update for Windows 10 Version 1607 for x86-based Systems (KB4512517)
PATCH-272232019-08 Cumulative Update for Windows 10 Version 1803 for x64-based Systems (KB4512501)
PATCH-272242019-08 Cumulative Update for Windows Server 2016 (1803) for x64-based Systems (KB4512501)
PATCH-272252019-08 Cumulative Update for Windows 10 Version 1803 for x86-based Systems (KB4512501)
PATCH-272212019-08 Cumulative Update for Windows 10 Version 1709 for x64-based Systems (KB4512516)
PATCH-272222019-08 Cumulative Update for Windows 10 Version 1709 for x86-based Systems (KB4512516)
PATCH-272292019-08 Cumulative Update for Windows 10 Version 1903 for x64-based Systems (KB4512508)
PATCH-272302019-08 Cumulative Update for Windows Server, version 1903 for x64-based Systems (KB4512508)
PATCH-272312019-08 Cumulative Update for Windows 10 Version 1903 for x86-based Systems (KB4512508)
PATCH-272152019-08 Cumulative Update for Windows 10 Version 1607 for x64-based Systems (KB4512517)
PATCH-272162019-08 Cumulative Update for Windows Server 2016 for x64-based Systems (KB4512517)
PATCH-272262019-08 Cumulative Update for Windows Server 2019 for x64-based Systems (KB4511553)
PATCH-272272019-08 Cumulative Update for Windows 10 Version 1809 for x64-based Systems (KB4511553)
PATCH-272282019-08 Cumulative Update for Windows 10 Version 1809 for x86-based Systems (KB4511553)
PATCH-272172019-08 Cumulative Update for Windows 10 Version 1507 for x86-based Systems (KB4512497)
PATCH-272182019-08 Cumulative Update for Windows 10 Version 1507 for x64-based Systems (KB4512497)
PATCH-324370Node.js 12 (12.22.12)
PATCH-331763Node.js 18 (x64) (18.17.0)
PATCH-331762Node.js 18 (18.17.0)
PATCH-319043Node.js 10 (x64) (10.24.1)
PATCH-319042Node.js 10 (10.24.1)
PATCH-324370Node.js 12 (12.22.12)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234