| Type | URI |
|---|---|
| Vendor Advisory | https://nghttp2.org/blog/2018/04/12/nghttp2-v1-31-1/ |
| Third Party Advisory | https://nodejs.org/en/blog/vulnerability/june-2018-security-releases/ |
| Third Party Advisory | http://www.securityfocus.com/bid/103952 |
| Third Party Advisory | https://access.redhat.com/errata/RHSA-2019:0367 |
| Third Party Advisory | https://access.redhat.com/errata/RHSA-2019:0366 |
| MLIST | https://lists.debian.org/debian-lts-announce/2021/10/msg00011.html |
| CPE URI | Source package | Min version | Max version |
|---|---|---|---|
cpe:2.3:a:nghttp2:nghttp2:*:*:*:*:*:*:*:* |
nghttp2 | >= 1.10.0 | <= 1.31.0 |
| Source package | Branch | Version | Maintainer | Status |
|---|---|---|---|---|
| nodejs | edge-main | 8.11.3-r0 | None | fixed |
| nodejs | 3.22-main | 8.11.3-r0 | None | fixed |
| nodejs | 3.21-main | 8.11.3-r0 | None | fixed |
| nodejs | 3.20-main | 8.11.3-r0 | None | fixed |
| nodejs | 3.19-main | 8.11.3-r0 | None | fixed |
| nodejs | 3.18-main | 8.11.3-r0 | None | fixed |
| nodejs | 3.17-main | 8.11.3-r0 | None | fixed |
| nodejs | 3.12-main | 8.11.3-r0 | None | fixed |
| nodejs | 3.11-main | 8.11.3-r0 | None | fixed |
| nodejs | 3.10-main | 8.11.3-r0 | None | fixed |