Index: head/security/vuxml/vuln.xml =================================================================== --- head/security/vuxml/vuln.xml +++ head/security/vuxml/vuln.xml @@ -58,6 +58,38 @@ * Do not forget port variants (linux-f10-libxml2, libxml2, etc.) --> + + h2o -- DoS in workers + + + h2o + 2.2.3 + + + + +

Frederik Deweerdt reports:

+
+

Multiple Denial-of-Service vulnerabilities exist in h2o workers - + see references for full details.

+

CVE-2017-10868: Worker processes may crash when receiving a request with invalid framing.

+

CVE-2017-10869: The stack may overflow when proxying huge requests.

+
+ +
+ + CVE-2017-10868 + CVE-2017-10869 + https://github.com/h2o/h2o/issues/1459 + https://github.com/h2o/h2o/issues/1460 + https://github.com/h2o/h2o/releases/tag/v2.2.3 + + + 2017-07-19 + 2017-10-17 + +
+ irssi -- multiple vulnerabilities