CVE-2018-16844
HIGH | Platform: Xcode | Changelog
CVE Details
Description
nginx before versions 1.15.6 and 1.14.1 has a vulnerability in the implementation of HTTP/2 that can allow for excessive CPU usage. This issue affects nginx compiled with the ngx_http_v2_module (not compiled by default) if the ‘http2’ option of the ’listen’ directive is used in a configuration file.
CVSS 3.1 Score
| Metric | Value |
|---|---|
| Base Score | 7.5 (HIGH) |
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Weakness
References
- Apple Security Advisory
- NVD Entry
- http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00035.html (Third Party Advisory)
- http://mailman.nginx.org/pipermail/nginx-announce/2018/000220.html (Mailing List, Vendor Advisory)
- http://seclists.org/fulldisclosure/2021/Sep/36 (Mailing List, Third Party Advisory)
- http://www.securityfocus.com/bid/105868 (Third Party Advisory, VDB Entry)
- http://www.securitytracker.com/id/1042038 (Third Party Advisory, VDB Entry)
- https://access.redhat.com/errata/RHSA-2018:3680 (Third Party Advisory)
- https://access.redhat.com/errata/RHSA-2018:3681 (Third Party Advisory)
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-16844 (Issue Tracking)