Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

Mageia 7: MGASA-2020-0147 Critical: Nghttp2 Malformed Request Exploit

mageia
Calendar Grey March 31, 2020
Dist Mageia Esm H88
Mageia Security Advisory MGASA-2020-0147 addresses a vulnerability in nghttp2 that arises from improperly formatted request headers, leading to potential elevation of privileges.
Malformed request header may cause route matchers or access controls to be bypassed, resulting in escalation of privileges or information disclosure (CVE-2019-18802)

Summary

Malformed request header may cause route matchers or access controls to be bypassed, resulting in escalation of privileges or information disclosure (CVE-2019-18802).

References

- https://bugs.mageia.org/show_bug.cgi?id=26361

- http://lists.suse.com/pipermail/sle-security-updates/2020-March/006627.html

- https://www.cve.org/CVERecord?id=CVE-2019-18802

Resolution

SRPMS

- 7/core/nghttp2-1.38.0-1.2.mga7

Severity
critical
Lowest
Low
Medium
High
Critical

Publication date: 01 Apr 2020
URL: https://advisories.mageia.org/MGASA-2020-0147.html
Type: security
CVE: CVE-2019-18802

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here