Index: security/vuxml/vuln/2023.xml =================================================================== --- security/vuxml/vuln/2023.xml +++ security/vuxml/vuln/2023.xml @@ -1,3 +1,37 @@ + + h2o -- Malformed HTTP/1.1 causes Out-of-Memory Denial of Service + + + h2o + 2.2.6 + + + h2o-devel + 2.3.0.d.20230427 + + + + +

Elijah Glover reports:

+
+

+ Malformed HTTP/1.1 requests can crash worker processes. + occasionally locking up child workers and causing denial of + service, and an outage dropping any open connections. +

+
+ +
+ + CVE-2023-30847 + https://github.com/h2o/h2o/security/advisories/GHSA-p5hj-phwj-hrvx + + + 2023-04-27 + 2023-04-30 + +
+ Gitlab -- Vulnerability @@ -445,40 +479,6 @@ - - h2o -- Malformed HTTP/1.1 causes Out-of-Memory Denial of Service - - - h2o - 2.2.6 - - - h2o-devel - 2.3.0.d.20230427 - - - - -

Elijah Glover reports:

-
-

- Malformed HTTP/1.1 requests can crash worker processes. - occasionally locking up child workers and causing denial of - service, and an outage dropping any open connections. -

-
- -
- - CVE-2023-30847 - https://github.com/h2o/h2o/security/advisories/GHSA-p5hj-phwj-hrvx - - - 2023-04-27 - 2023-04-30 - -
- git -- Multiple vulnerabilities