| Name | CVE-2019-9513 |
| Description | Some HTTP/2 implementations are vulnerable to resource loops, potentia ... |
| Source | CVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) |
| References | DSA-4505-1, DSA-4511-1, DSA-4669-1 |
| Debian Bugs | 934885, 935037 |
Vulnerable and fixed packages
The table below lists information on source packages.
| Source Package | Release | Version | Status |
|---|
| nghttp2 (PTS) | bullseye | 1.43.0-1+deb11u1 | fixed |
| bullseye (security) | 1.43.0-1+deb11u2 | fixed |
| bookworm | 1.52.0-1+deb12u2 | fixed |
| bookworm (security) | 1.52.0-1+deb12u1 | fixed |
| trixie | 1.64.0-1.1 | fixed |
| forky, sid | 1.69.0-1 | fixed |
| nginx (PTS) | bullseye | 1.18.0-6.1+deb11u3 | fixed |
| bullseye (security) | 1.18.0-6.1+deb11u5 | fixed |
| bookworm | 1.22.1-9+deb12u3 | fixed |
| bookworm (security) | 1.22.1-9+deb12u4 | fixed |
| trixie (security), trixie | 1.26.3-3+deb13u2 | fixed |
| forky, sid | 1.30.0-2 | fixed |
| nodejs (PTS) | bullseye | 12.22.12~dfsg-1~deb11u4 | fixed |
| bullseye (security) | 12.22.12~dfsg-1~deb11u7 | fixed |
| bookworm, bookworm (security) | 18.20.4+dfsg-1~deb12u1 | fixed |
| trixie | 20.19.2+dfsg-1 | fixed |
| trixie (security) | 20.19.2+dfsg-1+deb13u2 | fixed |
| forky | 22.22.2+dfsg+~cs22.19.15-3 | fixed |
| sid | 24.15.0+dfsg+~cs24.12.2-1 | fixed |
The information below is based on the following data on fixed versions.
Notes
[jessie] - nginx <not-affected> (HTTP2 support only exists since version 1.9.5)
[stretch] - nodejs <not-affected> (No HTTP2 support yet)
[jessie] - nodejs <not-affected> (No HTTP2 support yet)
[jessie] - nghttp2 <not-affected> (Vulnerable code not present)
https://www.nginx.com/blog/nginx-updates-mitigate-august-2019-http-2-vulnerabilities/
https://github.com/nginx/nginx/commit/5ae726912654da10a9a81b2c8436829f3e94f69f (master)
https://github.com/nginx/nginx/commit/39bb3b9d4a33bd03c8ae0134dedc8a7700ae7b2b (release-1.16.1)
https://github.com/Netflix/security-bulletins/blob/master/advisories/third-party/2019-002.md
https://nodejs.org/en/blog/vulnerability/aug-2019-security-releases/
https://github.com/nghttp2/nghttp2/releases/tag/v1.39.2