Bug ID 1208558
Summary VUL-0: CVE-2022-31394: gnome-podcasts: hyper: max header list size not settable allowing deny of service
Classification openSUSE
Product openSUSE Tumbleweed
Version Current
Hardware Other
URL https://smash.suse.de/issue/357841/
OS Other
Status NEW
Severity Normal
Priority P5 - None
Component Security
Assignee os.gnome.maintainers@gmail.com
Reporter thomas.leroy@suse.com
QA Contact security-team@suse.de
CC security-team@suse.de
Blocks 1208551
Found By Security Response Team
Blocker ---

+++ This bug was initially created as a clone of Bug #1208551 +++

CVE-2022-31394

Hyperium Hyper before 0.14.19 does not allow for customization of the
max_header_list_size method in the H2 third-party software, allowing attackers
to perform HTTP2 attacks.

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2022-31394
https://www.cve.org/CVERecord?id=CVE-2022-31394
https://github.com/hyperium/hyper/compare/v0.14.18...v0.14.19
https://github.com/hyperium/hyper/issues/2826
https://github.com/hyperium/hyper/pull/2828


You are receiving this mail because: