
====================================================================

                             CERT-Renater

                 Note d'Information No. 2019/VULN245

_____________________________________________________________________

DATE                : 29/08/2019

HARDWARE PLATFORM(S): /

OPERATING SYSTEM(S): Systems running nginx versions prior to 1.17.3,
                                          1.16.1.

=====================================================================
http://mailman.nginx.org/pipermail/nginx-announce/2019/000249.html
_____________________________________________________________________

Hello!

Several security issues were identified in nginx HTTP/2
implementation, which might cause excessive memory consumption
and CPU usage (CVE-2019-9511, CVE-2019-9513, CVE-2019-9516).

The issues affect nginx compiled with the ngx_http_v2_module (not
compiled by default) if the "http2" option of the "listen" directive
is used in a configuration file.

The issues affect nginx 1.9.5 - 1.17.2.
The issues are fixed in nginx 1.17.3, 1.16.1.

Thanks to Jonathan Looney from Netflix for discovering these issues.


-- 
Maxim Dounin
http://nginx.org/

=========================================================
+ CERT-RENATER        | tel : 01-53-94-20-44            +
+ 23/25 Rue Daviel    | fax : 01-53-94-20-41            +
+ 75013 Paris         | email:cert@support.renater.fr   +
=========================================================



