lib/http2/connection.c in H2O prior to 1.7.3 and 2.x prior to 2.0.0-beta5 mishandles HTTP/2 disconnection, which allows remote malicious users to cause a denial of service (use-after-free and application crash) or possibly execute arbitrary code via a crafted packet.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
dena h2o |