H2o: Format String Vulnerability (CVE-2016-4864)

Created on 14 Sep 2016  路  7Comments  路  Source: h2o/h2o

Format string vulnerability exists in H2O upto and including version 2.0.3 / 2.1.0-beta2, that can be used by remote attackers to mount Denial-of-Service attacks.

Users using one of the following handlers of H2O may be affected by the issue and are advised to upgrade immediately to version 2.0.4 or 2.1.0-beta3.

Affected handlers:

Deployments only using the file handler is not affected by the vulnerability.

vulnerability

All 7 comments

Hello,

I've updated following my binary package builder repositories too.

It is highly recommended to update if you use them.

What's the commit for the fix?

This landed in FreeBSD ports tree 10h00 UTC https://svnweb.freebsd.org/ports?view=revision&revision=422122 and will be backported to quarterly branch once ports-secteam approve it. Follow https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=211892 for more details.

@judofyr

What's the commit for the fix?

I am sorry but I am not sure if answering to the question at a public place would be a good thing to do at the moment. Please send me a mail if you need such information stating why you need it.

@kazuho Well, it's open-source after all, so what would be the risk in making the commit public? Your comment makes me feel quite strange.

11 months later it is ok, to make the fix public. So linking is ok now.

Was this page helpful?
0 / 5 - 0 ratings

Related issues

utrenkner picture utrenkner  路  8Comments

utrenkner picture utrenkner  路  3Comments

voiddeveloper picture voiddeveloper  路  6Comments

dch picture dch  路  5Comments

chenbd picture chenbd  路  3Comments