You are viewing an old version of this page. View the current version.

Compare with Current View Page History

« Previous Version 3 Next »

Summary

This table lists vendors and products affected by a set of vulnerabilities in HTTP/2 and QUIC implementations. For more information see vul note and researcher doc.

Matrix


VendorProductVersion

Data Dribble
CVE-2019-9511

Ping Flood
CVE-2019-9512

Resource Loop
CVE-2019-9513

Reset Flood
CVE-2019-9514

Settings Flood
CVE-2019-9515

0-Length Headers Leak (Nginx variant)
CVE-2019-9516

Internal Data Buffering
CVE-2019-9517

Empty Frames Flood
CVE-2019-9518

F5NGINX1.15.8

Affected

Addressed in

NYNNYNN
Go 1.12 (before Go 1.11.13 and Go 1.12.8)

NYNYNNNN
Netty 4.1.27

NYNY

Y
Apache 2.4.38

NNN
NNY
Apache Tomcat 9.0.13 (w/ FreeBSD native library 1.2.16)

NNBorderlineNNN

node.js 11.11.0 + libnghttp2 1.35.1

YNYYNY/NN
Microsoft IIS

YYYYNNNY
gRPC C 1.21.0

NNNYYNN
gRPC Java 1.21.0 (uses Netty)

NNNNYNN
gRPC Go 1.21.0

NNNYYNN
swift-nio-http2 1.0.0, 1.0.1, 1.1.0, 1.2.0, 1.2.1, 1.3.0, 1.4.0

NYNYYYNY
hyper-2 (Python)

NNNNNN

Twisted  16.3.0, 16.3.1, 16.3.2, 16.4.0, 16.4.1, 16.5.0, 16.6.0, 17.1.0, 17.5.0, 17.9.0, 18.4.0, 18.7.0, 18.9.0, 19.2.0, 19.2.1, 19.7.0

NYNYNNN
nghttp2

YNYNNNN
Apache Traffic Server

NYNYYNN
Envoy (all versions prior to 1.11.1)

NYYYYNNY
proxygen

NYYYYNN




References

some urls?

  • No labels