Oval Definition:oval:com.ubuntu.disco:def:201995170000000
Revision Date:2019-08-13Version:1
Title:CVE-2019-9517 on Ubuntu 19.04 (disco) - medium.
Description:Some HTTP/2 implementations are vulnerable to unconstrained interal data buffering, potentially leading to a denial of service. The attacker opens the HTTP/2 window so the peer can send without constraint; however, they leave the TCP window closed so the peer cannot actually write (many of) the bytes on the wire. The attacker then sends a stream of requests for a large response object. Depending on how the servers queue the responses, this can consume excess memory, CPU, or both.
Family:unixClass:vulnerability
Status:Reference(s):CVE-2019-9517
Platform(s):Ubuntu 19.04
Product(s):
Definition Synopsis
  • Ubuntu 19.04 (disco) is installed.
  • AND apache2 package in disco was vulnerable but has been fixed (note: '2.4.38-2ubuntu2.2').
  • BACK