SB2019081370 - Resource exhaustion in nodejs (Alpine package)
Published: August 13, 2019
Security Bulletin ID
SB2019081370
Severity
Medium
Patch available
YES
Number of vulnerabilities
1
Exploitation vector
Remote access
Highest impact
Denial of service
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Resource exhaustion (CVE-ID: CVE-2019-9511)
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to improper input validation when processing HTTP/2 requests. A remote attacker can send a specially crafted HTTP/2 request the affected server, consume all available CPU resources and perform a denial of service (DoS) attack.
Successful exploitation of the vulnerability requires that support for HTTP/2 is enabled.
Remediation
Install update from vendor's website.
References
- https://git.alpinelinux.org/aports/commit/?id=0b95f9e7ef4f4ff23e543297818706a10536a19a
- https://git.alpinelinux.org/aports/commit/?id=c9b014acf671adf0174919f3f74caca671717ee9
- https://git.alpinelinux.org/aports/commit/?id=fe7417f5c2fd0ea8b513ce1f1eeebf14f20eb56d
- https://git.alpinelinux.org/aports/commit/?id=1fb036fb0a10b3ee95720656cf3537469ab6930a
- https://git.alpinelinux.org/aports/commit/?id=d28d7200169ede5fa2d87cba9d1eeb3a459ae2a3
- https://git.alpinelinux.org/aports/commit/?id=732a2a015029f60efed0ccc9118d8a16bf7f860e
- https://git.alpinelinux.org/aports/commit/?id=1dc7b4f0c96ed51dcf6d72c6251e6bb4f6ff24ea
- https://git.alpinelinux.org/aports/commit/?id=7e54a7f5951458ed9cb54587080165d03b20d06d
- https://git.alpinelinux.org/aports/commit/?id=30aecaf3fcad1d9f048bad8e181f267d40bc336c
- https://git.alpinelinux.org/aports/commit/?id=578c97338a5cc6615df123d2759ef349dbf88c2c
- https://git.alpinelinux.org/aports/commit/?id=75cc679dead3d9b8aebb82a11c1f81a4eaaab853
- https://git.alpinelinux.org/aports/commit/?id=7149c919df587e3f9125fdac8bc2ccd4952027e3
- https://git.alpinelinux.org/aports/commit/?id=181112be362642a3beea5c67e21985f3364b7b23
- https://git.alpinelinux.org/aports/commit/?id=6e8dc30ce258648d95eb57892b407d0ae7b72981
- https://git.alpinelinux.org/aports/commit/?id=8a20f72a0662540e2965493e72f68b22ffb975ff
- https://git.alpinelinux.org/aports/commit/?id=68587782ed49631dadd84c5a6aaf0380aabf30fb
- https://git.alpinelinux.org/aports/commit/?id=cbfc890c785c113b462f0cb5bbbe873503b00c9f
- https://git.alpinelinux.org/aports/commit/?id=45003dac9059e38b73687135bba6c67874b992a2