Alerts This Week
Warning Icon 1 626
Alerts This Week
Warning Icon 1 626

SUSE: 2019:2260-1 Important: Nodejs8 Denial Of Service Issues

suse
Calendar Grey September 2, 2019
Dist Suse Esm H88
Get vital updates on SUSE's nodejs8 security patch fixing multiple denial of service issues with effective solutions.
An update that solves 8 vulnerabilities and has one errata is now available

Summary

This update for nodejs8 to version 8.16.1 fixes the following issues: Security issues fixed: - CVE-2019-9511: Fixed HTTP/2 implementations that are vulnerable to window size manipulation and stream prioritization manipulation, potentially leading to a denial of service (bsc#1146091). - CVE-2019-9512: Fixed HTTP/2 flood using PING frames results in unbounded memory growth (bsc#1146099). - CVE-2019-9513: Fixed HTTP/2 implementation that is vulnerable to resource loops, potentially leading to a denial of service. (bsc#1146094). - CVE-2019-9514: Fixed HTTP/2 implementation that is vulnerable to a reset flood, potentially leading to a denial of service (bsc#1146095). - CVE-2019-9515: Fixed HTTP/2 flood using SETTINGS frames results in unbounded memory growth (bsc#1146100).

References

#1144919 #1146090 #1146091 #1146093 #1146094

#1146095 #1146097 #1146099 #1146100

Cross- CVE-2019-9511 CVE-2019-9512 CVE-2019-9513

CVE-2019-9514 CVE-2019-9515 CVE-2019-9516

CVE-2019-9517 CVE-2019-9518

Affected Products:

SUSE Linux Enterprise Module for Web Scripting 15-SP1

SUSE Linux Enterprise Module for Web Scripting 15

https://www.suse.com/security/cve/CVE-2019-9511.html

https://www.suse.com/security/cve/CVE-2019-9512.html

https://www.suse.com/security/cve/CVE-2019-9513.html

https://www.suse.com/security/cve/CVE-2019-9514.html

https://www.suse.com/security/cve/CVE-2019-9515.html

https://www.suse.com/security/cve/CVE-2019-9516.html

https://www.suse.com/security/cve/CVE-2019-9517.html

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2019:2260-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here