Bug ID 1073952
Summary [server:http] h20: multiple security issues
Classification openSUSE
Product openSUSE Distribution
Version Leap 42.3
Hardware Other
URL https://smash.suse.de/issue/197162/
OS Other
Status NEW
Severity Normal
Priority P5 - None
Component Other
Assignee mrueckert@suse.com
Reporter meissner@suse.com
QA Contact security-team@suse.de
Found By Security Response Team
Blocker ---

CVE-2017-10869 [h2o 2.2.x: stack overflow when sending huge request body to
upstream]
CVE-2017-10868 [h2o 2.2.x: crash when receiving HTTP/1 request with invalid
framing]
CVE-2017-10908 [h2o 2.2.x: crash when handling malformed HTTP/2 request]
CVE-2017-10872 [h2o: 2.2.x: crash when logging TLS 1.3 properties in h2o]

package is only in server:http as far as I see.


You are receiving this mail because: