Re: Vulnerability making News - HTTP/2 Rapid Reset DDoS CVE-2023-44487
"Mayekar, PrachiX" <[email protected]> Mon, 16 Oct 2023 08:10:14 +0000
| Newsgroups | gmane.comp.syslog-ng |
|---|---|
| Message-ID | <MW4PR11MB67409B2A34BED4A22F79276FF0D7A@MW4PR11MB6740.namprd11.prod.outlook.com> |
Hi Team, Are syslog products vulnerable to this vulnerability ? Need to know if Syslog is affected: CVE-2023-44487 is a vulnerability in the HTTP/2 protocol that was recently used to launch DDoS attacks. The vulnerability allows for denial of service (DoS) because request cancellation can reset many streams quickly. https://www.bleepingcomputer.com/news/security/new-http-2-rapid-reset-zero-day-attack-breaks-ddos-records/ Thanks & Regards, Prachi Mayekar ITI-Network Services A Contingent Worker at Intel For assistance, please visit us at https://it.intel.com<https://it.intel.com/> ______________________________________________________________________________ Member info: https://lists.balabit.hu/mailman/listinfo/syslog-ng Documentation: http://www.balabit.com/support/documentation/?product=syslog-ng FAQ: http://www.balabit.com/wiki/syslog-ng-faq