MGASA-2020-0147 - Updated nghttp2 packages fix security vulnerability

Publication date: 01 Apr 2020
URL: https://advisories.mageia.org/MGASA-2020-0147.html
Type: security
Affected Mageia releases: 7
CVE: CVE-2019-18802

Malformed request header may cause route matchers or access controls to be
bypassed, resulting in escalation of privileges or information disclosure
(CVE-2019-18802).

References:
- https://bugs.mageia.org/show_bug.cgi?id=26361
- http://lists.suse.com/pipermail/sle-security-updates/2020-March/006627.html
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-18802

SRPMS:
- 7/core/nghttp2-1.38.0-1.2.mga7

Mageia 2020-0147: nghttp2 security update

Malformed request header may cause route matchers or access controls to be bypassed, resulting in escalation of privileges or information disclosure (CVE-2019-18802)

Summary

Malformed request header may cause route matchers or access controls to be bypassed, resulting in escalation of privileges or information disclosure (CVE-2019-18802).

References

- https://bugs.mageia.org/show_bug.cgi?id=26361

- http://lists.suse.com/pipermail/sle-security-updates/2020-March/006627.html

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-18802

Resolution

MGASA-2020-0147 - Updated nghttp2 packages fix security vulnerability

SRPMS

- 7/core/nghttp2-1.38.0-1.2.mga7

Severity
Publication date: 01 Apr 2020
URL: https://advisories.mageia.org/MGASA-2020-0147.html
Type: security
CVE: CVE-2019-18802

Related News