VDB
BDU%3A2019-02997
BDU%3A2019-02997
PUBLISHED
CVSS 7.800000190734863 HIGH
Уязвимость реализации сетевого протокола HTTP/2 операционных систем Windows, веб-сервера Apache Traffic Server, сетевых программных средств Envoy, программной платформы Node.js, позволяющая нарушителю вызвать отказ в обслуживании
Risk Scores
CVSS 2.0
7.800000190734863
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Microsoft Corp, Сообщество свободного программного обеспечения, ООО «РусБИТех-Астра», Fedora Project, Red Hat Inc., Novell Inc., Node.js Foundation, Apache Software Foundation, Oracle Corp., АО «Концерн ВНИИНС» | Windows 10, Windows 10 1607, Windows 10 1703, Windows Server 2016, Windows Server 2016 (Server Core installation), Debian GNU/Linux, Windows 10 1709, Windows 10 1803, Windows Server 1803 (Server Core Installation), Windows 10 1809, Windows Server 2019, Windows Server 2019 (Server Core installation), Astra Linux Special Edition (запись в едином реестре российских программ №369), Fedora, Windows 10 1903, Windows Server 1903 (Server Core Installation), Red Hat Enterprise Linux, OpenSUSE Leap, Envoy, Node.js, Traffic Server, Red Hat Software Collections, Astra Linux Special Edition для «Эльбрус» (запись в едином реестре российских программ №11156), Oracle Communications Session Border Controller, Enterprise Communications Broker, ОС ОН «Стрелец» (запись в едином реестре российских программ №6177) |
Timeline
- Aug 27, 2019 CVE Published
- Nov 21, 2023 CVE Updated
- Mar 18, 2026 Security Advisory
- Mar 18, 2026 Security Advisory
- Mar 18, 2026 Security Advisory
- Mar 18, 2026 Security Advisory
- Mar 18, 2026 Security Advisory
- Mar 18, 2026 Security Advisory
- Mar 18, 2026 Security Advisory
References
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-9513 url
- https://lists.apache.org/thread.html/ad3d01e767199c1aed8033bb6b3f5bf98c011c7c536f07a5d34b3c19@%3Cannounce.trafficserver.apache.org%3E url
- https://lists.apache.org/thread.html/392108390cef48af647a2e47b7fd5380e050e35ae8d1aa2030254c04@%3Cusers.trafficserver.apache.org%3E url
- https://lists.apache.org/thread.html/bde52309316ae798186d783a5e29f4ad1527f61c9219a289d0eee0a7@%3Cdev.trafficserver.apache.org%3E url
- https://blog.getambassador.io/multiple-http-2-vulnerabilities-in-envoy-proxy-59351babb3aa url
- https://nodejs.org/en/blog/vulnerability/aug-2019-security-releases/ url
- https://security-tracker.debian.org/tracker/CVE-2019-9513 url
- http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00031.html url
- http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00032.html url
- http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00035.html url
- http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00003.html url
- http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00005.html url
- http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00014.html url
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4ZQGHE3WTYLYAYJEIDJVF2FIGQTAYPMC/ url
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/CMNFX5MNYRWWIMO4BTKYQCGUDMHO3AXP/ url
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/JUBYAF6ED3O4XCHQ5C2HYENJLXYXZC4M/ url
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LZLUYPYY3RX4ZJDWZRJIKSULYRJ4PXW7/ url
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/POPAEC4FWL4UU4LDEGPY5NPALU24FFQD/ url
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/TAZZEVTCN2B4WT6AIBJ7XGYJMBTORJU5/ url
- https://access.redhat.com/security/cve/cve-2019-9513 url
…and 5 more