The idle stream handling in nghttp2 before 1.6.0 allows attackers to have unspecified impact via unknown vectors, aka a heap-use-after-free bug.
References
Information
Published : 2016-01-12 11:59
Updated : 2019-03-08 08:06
NVD link : CVE-2015-8659
Mitre link : CVE-2015-8659
JSON object : View
CWE
CWE-119
Improper Restriction of Operations within the Bounds of a Memory Buffer
Products Affected
apple
- tvos
- mac_os_x
- watchos
- iphone_os
nghttp2
- nghttp2