View | Details | Raw Unified | Return to bug 247713 | Differences between
and this patch

Collapse All | Expand All

(-)vuln.xml (+26 lines)
Line 60 Link Here
61
  <vuln vid="6fd773d3-bc5a-11ea-b38d-f0def1d0c3ea">
62
    <topic>trafficserver -- resource consumption</topic>
63
    <affects>
64
      <package>
65
	<name>trafficserver</name>
66
	<range><lt>8.0.8</lt></range>
67
      </package>
68
    </affects>
69
    <description>
70
      <body xmlns="http://www.w3.org/1999/xhtml">
71
	<p>Bryan Call reports:</p>
72
	<blockquote cite="https://lists.apache.org/thread.html/rf7f86917f42fdaf904d99560cba0c016e03baea6244c47efeb60ecbe%40%3Cdev.trafficserver.apache.org%3E">
73
	  <p>ATS is vulnerable to certain types of HTTP/2 HEADERS frames that can cause the server to allocate a large amount of memory and spin the thread.</p>
74
	</blockquote>
75
      </body>
76
    </description>
77
    <references>
78
      <url>https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-9494</url>
79
      <cvename>CVE-2020-9494</cvename>
80
    </references>
81
    <dates>
82
      <discovery>2020-06-24</discovery>
83
      <entry>2020-07-02</entry>
84
    </dates>
85
  </vuln>
86

Return to bug 247713