CVE-2019-9518

Description

Some HTTP/2 implementations are vulnerable to a flood of empty frames, potentially leading to a denial of service. The attacker sends a stream of frames with an empty payload and without the end-of-stream flag. These frames can be DATA, HEADERS, CONTINUATION and/or PUSH_PROMISE. The peer spends time processing each frame disproportionate to attack bandwidth. This can consume excess CPU.

Risk Information

Base Score
7.5
MODERATE
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:P/RL:O/RC:C
EPSS Score
Exploitation Probability
3.674

Associated Vulnerability

VulnerabilityOS Platform
Windows Information Disclosure Vulnerability for Windows 10 Version 1607 for x86-based Systems (KB4512517)Windows
Windows Information Disclosure Vulnerability for Windows 10 Version 1803 for x64-based Systems (KB4512501)Windows
Windows Information Disclosure Vulnerability for Windows Server 2016 (1803) for x64-based Systems (KB4512501)Windows
Windows Information Disclosure Vulnerability for Windows 10 Version 1803 for x86-based Systems (KB4512501)Windows
Windows Information Disclosure Vulnerability for Windows 10 Version 1709 for x64-based Systems (KB4512516)Windows
Windows Information Disclosure Vulnerability for Windows 10 Version 1709 for x86-based Systems (KB4512516)Windows
Windows Information Disclosure Vulnerability for Windows 10 Version 1903 for x64-based Systems (KB4512508)Windows
Windows Information Disclosure Vulnerability for Windows Server, version 1903 for x64-based Systems (KB4512508)Windows
Windows Information Disclosure Vulnerability for Windows 10 Version 1903 for x86-based Systems (KB4512508)Windows
Windows Information Disclosure Vulnerability for Windows 10 Version 1703 for x64-based Systems (KB4512507)Windows
Windows Information Disclosure Vulnerability for Windows 10 Version 1703 for x86-based Systems (KB4512507)Windows
Windows Information Disclosure Vulnerability for Windows 10 Version 1607 for x64-based Systems (KB4512517)Windows
Windows Information Disclosure Vulnerability for Windows Server 2016 for x64-based Systems (KB4512517)Windows
Windows Information Disclosure Vulnerability for Windows Server 2019 for x64-based Systems (KB4511553)Windows
Windows Information Disclosure Vulnerability for Windows 10 Version 1809 for x64-based Systems (KB4511553)Windows
Windows Information Disclosure Vulnerability for Windows 10 Version 1809 for x86-based Systems (KB4511553)Windows
Windows Information Disclosure Vulnerability for Windows 10 Version 1507 for x86-based Systems (KB4512497)Windows
Windows Information Disclosure Vulnerability for Windows 10 Version 1507 for x64-based Systems (KB4512497)Windows
Windows Information Disclosure Vulnerability for Windows 10 Version 1703 for x64-based Systems (KB4512507)Windows
Windows Information Disclosure Vulnerability for Windows 10 Version 1703 for x86-based Systems (KB4512507)Windows
Windows Information Disclosure Vulnerability for Windows 10 Version 1703 for x64-based Systems (KB4512507)Windows
Windows Information Disclosure Vulnerability for Windows 10 Version 1703 for x86-based Systems (KB4512507)Windows
Multiple vulnerabilities are fixed in Node.js 12 (12.22.12)Windows
Multiple vulnerabilities are fixed in Node.js 18 (x64) (18.16.1)Windows
Multiple vulnerabilities are fixed in Node.js 18 (18.16.1)Windows
Multiple vulnerabilities are fixed in Node.js (x64) (10.16.3)Windows
Multiple vulnerabilities are fixed in Node.js (10.16.3)Windows
Multiple vulnerabilities are fixed in Node.js 8 8.16.1Windows
Multiple vulnerabilities are fixed in Node.js 8 (x64) 8.16.1Windows
Multiple vulnerabilities are fixed in Node.js 12 12.8.1Windows
Multiple Vulnerabilities are affected in IBM Sterling B2B Integrator 6.0.3.1Windows
Multiple Vulnerabilities are affected in Red Hat JBoss Enterprise Application Platform 7 7.2.0Windows
Multiple Vulnerabilities are affected in IBM Sterling B2B Integrator 5.2.6.5Windows
Multiple Vulnerabilities are affected in Red Hat JBoss Enterprise Application Platform 7 7.3.0Windows
Multiple Vulnerabilities are affected in IBM MQ 9.1Windows
Multiple Vulnerabilities are affected in IBM Tivoli Application Dependency Discovery Manager 7.3.0.7Windows
trafficserver security update(DSA-4520-1) trafficserver_8.0.2+ds-1+deb10u1_amd64.debLinux
Allocation of Resources Without Limits or Throttling Vulnerability (CVE-2019-9518)NCM

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-272142019-08 Cumulative Update for Windows 10 Version 1607 for x86-based Systems (KB4512517)
PATCH-272232019-08 Cumulative Update for Windows 10 Version 1803 for x64-based Systems (KB4512501)
PATCH-272242019-08 Cumulative Update for Windows Server 2016 (1803) for x64-based Systems (KB4512501)
PATCH-272252019-08 Cumulative Update for Windows 10 Version 1803 for x86-based Systems (KB4512501)
PATCH-272212019-08 Cumulative Update for Windows 10 Version 1709 for x64-based Systems (KB4512516)
PATCH-272222019-08 Cumulative Update for Windows 10 Version 1709 for x86-based Systems (KB4512516)
PATCH-272292019-08 Cumulative Update for Windows 10 Version 1903 for x64-based Systems (KB4512508)
PATCH-272302019-08 Cumulative Update for Windows Server, version 1903 for x64-based Systems (KB4512508)
PATCH-272312019-08 Cumulative Update for Windows 10 Version 1903 for x86-based Systems (KB4512508)
PATCH-272152019-08 Cumulative Update for Windows 10 Version 1607 for x64-based Systems (KB4512517)
PATCH-272162019-08 Cumulative Update for Windows Server 2016 for x64-based Systems (KB4512517)
PATCH-272262019-08 Cumulative Update for Windows Server 2019 for x64-based Systems (KB4511553)
PATCH-272272019-08 Cumulative Update for Windows 10 Version 1809 for x64-based Systems (KB4511553)
PATCH-272282019-08 Cumulative Update for Windows 10 Version 1809 for x86-based Systems (KB4511553)
PATCH-272172019-08 Cumulative Update for Windows 10 Version 1507 for x86-based Systems (KB4512497)
PATCH-272182019-08 Cumulative Update for Windows 10 Version 1507 for x64-based Systems (KB4512497)
PATCH-324370Node.js 12 (12.22.12)
PATCH-331763Node.js 18 (x64) (18.17.0)
PATCH-331762Node.js 18 (18.17.0)
PATCH-319043Node.js 10 (x64) (10.24.1)
PATCH-319042Node.js 10 (10.24.1)
PATCH-324370Node.js 12 (12.22.12)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234