CVE Database
/

CVE-2016-4817

Back to search

CVE-2016-4817

Published: Jun 19, 2016

Modified: Aug 6, 2024

PUBLISHED

Description

lib/http2/connection.c in H2O before 1.7.3 and 2.x before 2.0.0-beta5 mishandles HTTP/2 disconnection, which allows remote attackers to cause a denial of service (use-after-free and application crash) or possibly execute arbitrary code via a crafted packet.

VendorProductVersions

n/a

n/a

affected
n/a

References

JVN#87859762
third-party-advisory
x_refsource_JVN
JVNDB-2016-000091
third-party-advisory
x_refsource_JVNDB

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now
CVE-2016-4817 - Security Vulnerability | QwikSec