CVE-2020-9494
Summary
| CVE | CVE-2020-9494 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-06-24 16:15:00 UTC |
| Updated | 2021-07-21 11:39:00 UTC |
| Description | Apache Traffic Server 6.0.0 to 6.2.3, 7.0.0 to 7.1.10, and 8.0.0 to 8.0.7 is vulnerable to certain types of HTTP/2 HEADERS frames that can cause the server to allocate a large amount of memory and spin the thread. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Pony Mail! |
CONFIRM |
lists.apache.org |
Mailing List, Vendor Advisory |
| Debian -- Security Information -- DSA-4710-1 trafficserver |
DEBIAN |
www.debian.org |
Third Party Advisory |
| oss-security - CVE-2021-25329: Apache Tomcat Incomplete fix for CVE-2020-9484 |
MLIST |
www.openwall.com |
Not Applicable |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 178492 Debian Security Update for tomcat8 (DLA 2596-1)
- 198724 Ubuntu Security Notification for Tomcat Vulnerabilities (USN-5360-1)
- 670219 EulerOS Security Update for tomcat (EulerOS-SA-2021-1856)
- 670309 EulerOS Security Update for tomcat (EulerOS-SA-2021-1915)
- 670333 EulerOS Security Update for tomcat (EulerOS-SA-2021-1891)
- 670677 EulerOS Security Update for tomcat (EulerOS-SA-2021-2435)
- 690538 Free Berkeley Software Distribution (FreeBSD) Security Update for trafficserver (6fd773d3-bc5a-11ea-b38d-f0def1d0c3ea)