Project

General

Custom queries

Profile

Actions

Security #5926

closed

http2: evasion by splitting header fields over frames

Added by Philippe Antoine about 2 years ago. Updated over 1 year ago.

Status:
Closed
Priority:
Normal
Target version:
Affected Versions:
Label:
Git IDs:

aff54f29f8c3f583ae0524a661aa90dc7a2d3f92

Severity:
HIGH
Disclosure Date:

Description

Beginning in a headers frame, and continuing in so-called continuation frames, with reassembly needed to be done...

Then, we need to avoid quadratic complexity of Huffman decoding as golang CVE 2023-1571


Files

cont.pcap (2.53 KB) cont.pcap Philippe Antoine, 12/19/2023 08:33 PM

Subtasks 2 (0 open2 closed)

Security #6717: http2: evasion by splitting header fields over frames (7.0.x backport)ClosedPhilippe AntoineActions
Security #6751: http2: evasion by splitting header fields over frames (6.0.x backport)ClosedPhilippe AntoineActions
#1

Updated by Philippe Antoine almost 2 years ago

  • Target version changed from TBD to 8.0.0-beta1
#2

Updated by Philippe Antoine over 1 year ago

  • Priority changed from Normal to Low
#3

Updated by Philippe Antoine over 1 year ago

#4

Updated by Philippe Antoine over 1 year ago

  • Tracker changed from Bug to Security
  • Severity set to MODERATE
#5

Updated by Philippe Antoine over 1 year ago

  • Priority changed from Low to Normal
#6

Updated by Philippe Antoine over 1 year ago

  • Status changed from New to In Review
#9

Updated by Victor Julien over 1 year ago

  • Label Needs backport to 7.0 added
#10

Updated by OISF Ticketbot over 1 year ago

  • Subtask #6717 added
#11

Updated by OISF Ticketbot over 1 year ago

  • Label deleted (Needs backport to 7.0)
#12

Updated by Jason Ish over 1 year ago

  • Label Needs backport to 6.0 added
#13

Updated by OISF Ticketbot over 1 year ago

  • Subtask #6751 added
#14

Updated by OISF Ticketbot over 1 year ago

  • Label deleted (Needs backport to 6.0)
#15

Updated by Victor Julien over 1 year ago

  • CVE set to 2024-24568
#16

Updated by Philippe Antoine over 1 year ago

  • Status changed from In Review to Closed
  • Git IDs updated (diff)
#17

Updated by Philippe Antoine over 1 year ago

  • Severity changed from MODERATE to HIGH
#18

Updated by Victor Julien over 1 year ago

  • Private changed from Yes to No
Actions

Also available in: Atom PDF