Linux Distros Unpatched Vulnerability : CVE-2019-9515
Discription

image
The Linux/Unix host has one or more packages installed that are impacted by a vulnerability without a vendor supplied patch available. Some HTTP/2 implementations are vulnerable to a settings flood, potentially leading to a denial of service. The attacker sends a stream of SETTINGS frames to the peer. Since the RFC requires that the peer reply with one acknowledgement per SETTINGS frame, an empty SETTINGS frame is almost equivalent in behavior to a ping. Depending on how efficiently this data is queued, this can consume excess CPU, memory, or both. (CVE-2019-9515) Note that Nessus relies on the presence of the package as reported by the vendor. File data…Read More

Back to Main

Subscribe for the latest news: