You are viewing an old version of this page. View the current version.

Compare with Current View Page History

« Previous Version 6 Next »

Summary

This table lists vendors and products affected by a set of vulnerabilities in multiple HTTP/2 implementations. For more information see VU#605641 and NFLX-2019-002.

Matrix

VendorProduct

Affected Versions

Data Dribble
CVE-2019-9511

Ping Flood
CVE-2019-9512

Resource Loop
CVE-2019-9513

Reset Flood
CVE-2019-9514

Settings Flood
CVE-2019-9515

0-Length Headers Leak
CVE-2019-9516

Internal Data Buffering
CVE-2019-9517

Empty Frames Flood
CVE-2019-9518

F5NGINX1.15.8

Affected

Addressed in

NYNNYNN
Go 1.12 (before Go 1.11.13 and Go 1.12.8)

NYNYNNNN
Netty ProjectNetty4.1.27Not affected

Affected

https://netty.io/news/2019/08/13/4-1-39-Final.html

Not affected

Affected

https://netty.io/news/2019/08/13/4-1-39-Final.html

Affected

https://netty.io/news/2019/08/13/4-1-39-Final.html
Not affectedNot affected

Affected

https://netty.io/news/2019/08/13/4-1-39-Final.html
Apache 2.4.38
2.4.38NNN
NNY
Apache Tomcat 9.0.13 (w/ FreeBSD native library 1.2.16)

NNBorderlineNNN

node.js 11.11.0 + libnghttp2 1.35.1

YNYYNY/NN
Microsoft IIS

YYYYNNNY
gRPC C 1.21.0

NNNYYNN
gRPC Java 1.21.0 (uses Netty)

NNNNYNN
gRPC Go 1.21.0

NNNYYNN
swift-nio-http2 1.0.0, 1.0.1, 1.1.0, 1.2.0, 1.2.1, 1.3.0, 1.4.0

NYNYYYNY
hyper-2 (Python)

NNNNNN

Twisted  16.3.0, 16.3.1, 16.3.2, 16.4.0, 16.4.1, 16.5.0, 16.6.0, 17.1.0, 17.5.0, 17.9.0, 18.4.0, 18.7.0, 18.9.0, 19.2.0, 19.2.1, 19.7.0

NYNYNNN
nghttp2

YNYNNNN
Apache Traffic Server

NYNYYNN
EnvoyEnvoyPrior to 1.11.1Not affected

Affected

https://groups.google.com/forum/#!topic/envoy-announce/ZLchtraPYVk

Affected

https://groups.google.com/forum/#!topic/envoy-announce/ZLchtraPYVk

Affected

https://groups.google.com/forum/#!topic/envoy-announce/ZLchtraPYVk

Affected

https://groups.google.com/forum/#!topic/envoy-announce/ZLchtraPYVk
Not affectedNot affected

Affected

https://groups.google.com/forum/#!topic/envoy-announce/ZLchtraPYVk
proxygen

NYYYYNN

Other References

https://blog.cloudflare.com/on-the-recent-http-2-dos-attacks/


  • No labels