[arch-security] [ASA-201512-16] nghttp2: use-after-free
rgacogne at archlinux.org
Fri Dec 25 17:21:18 UTC 2015
Arch Linux Security Advisory ASA-201512-16
Date : 2015-12-25
CVE-ID : CVE-2015-8659
Package : nghttp2
Type : use-after-free
Remote : Yes
Link : https://wiki.archlinux.org/index.php/CVE
The package nghttp2 before version 1.6.0-1 is vulnerable to a heap-based
use-after-free, leading to denial of service or possibly arbitrary code
Upgrade to 1.6.0-1.
# pacman -Syu "nghttp2>=1.6.0-1"
The problem has been fixed upstream in version 1.6.0.
nghttp2 1.6.0 fixes a heap-based use-after-free bug in idle stream
handling code, where an idle/closed stream could possibly be destroyed
while it was still referenced.
A remote attacker could exploit this bug in a HTTP/2 client or server,
leading to denial of service or even arbitrary code execution.
-------------- next part --------------
A non-text attachment was scrubbed...
Size: 801 bytes
Desc: OpenPGP digital signature
More information about the arch-security